<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle" type="text/css">P {margin-top:0;margin-bottom:0;}</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;">Hello,<br>
<div><br>
just getting around to looking at this warning we've been getting for years. Everything has been working fine but every Google login generates one of these warnings:<br>
<br>
WARN [org.opensaml.saml2.binding.encoding.BaseSAML2MessageEncoder:134] - Relay state exceeds 80 bytes, some application may not support this.<br>
<br>
<rp:RelyingParty id="google.com"<br>
provider="https://shibboleth.uic.edu/shibboleth"<br>
defaultSigningCredentialRef="IdPCredential"<br>
defaultAuthenticationMethod="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"><br>
<rp:ProfileConfiguration xsi:type="saml:ShibbolethSSOProfile" /><br>
<rp:ProfileConfiguration xsi:type="saml:SAML1AttributeQueryProfile" /><br>
<rp:ProfileConfiguration xsi:type="saml:SAML2SSOProfile" encryptAssertions="never" encryptNameIds="never" /><br>
<rp:ProfileConfiguration xsi:type="saml:SAML2AttributeQueryProfile" /><br>
</rp:RelyingParty><br>
<br>
<br>
<!-- Google Apps --><br>
<!-- Do not release transientID to google.com - things break --><br>
<afp:AttributeFilterPolicy id="google.com"><br>
<afp:PolicyRequirementRule xsi:type="basic:AttributeRequesterString" value="google.com" /><br>
<afp:AttributeRule attributeID="principal"> <afp:PermitValueRule xsi:type="basic:ANY" /> </afp:AttributeRule><br>
</afp:AttributeFilterPolicy><br>
<br>
We've commented out the releaseTransientIdToAnyone policy and explicitly release transientID in all other policies. Other SP logins do not generate this message.<br>
<br>
What's the cause and is there a solution?<br>
<br>
<br>
<div style="font-family:Tahoma; font-size:13px">---
<div>Roberto Ullfig - ACCC Research Programmer<br>
<div>rullfig@uic.edu</div>
</div>
</div>
</div>
</div>
</body>
</html>