<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle" type="text/css">P {margin-top:0;margin-bottom:0;}</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;">Hello,<br>
<div><br>
just getting around to looking at this warning we've been getting for years. Everything has been working fine but every Google login generates one of these warnings:<br>
<br>
WARN [org.opensaml.saml2.binding.encoding.BaseSAML2MessageEncoder:134] - Relay state exceeds 80 bytes, some application may not support this.<br>
<br>
&nbsp;&nbsp;&nbsp; &lt;rp:RelyingParty id=&quot;google.com&quot;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; provider=&quot;https://shibboleth.uic.edu/shibboleth&quot;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; defaultSigningCredentialRef=&quot;IdPCredential&quot;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; defaultAuthenticationMethod=&quot;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;rp:ProfileConfiguration xsi:type=&quot;saml:ShibbolethSSOProfile&quot; /&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML1AttributeQueryProfile&quot; /&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2SSOProfile&quot; encryptAssertions=&quot;never&quot; encryptNameIds=&quot;never&quot; /&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2AttributeQueryProfile&quot; /&gt;<br>
&nbsp;&nbsp;&nbsp; &lt;/rp:RelyingParty&gt;<br>
<br>
<br>
&lt;!-- Google Apps --&gt;<br>
&lt;!-- Do not release transientID to google.com - things break --&gt;<br>
&nbsp;&nbsp;&nbsp; &lt;afp:AttributeFilterPolicy id=&quot;google.com&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PolicyRequirementRule xsi:type=&quot;basic:AttributeRequesterString&quot; value=&quot;google.com&quot; /&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule attributeID=&quot;principal&quot;&gt; &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot; /&gt; &lt;/afp:AttributeRule&gt;<br>
&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeFilterPolicy&gt;<br>
<br>
We've commented out the releaseTransientIdToAnyone policy and explicitly release transientID in all other policies. Other SP logins do not generate this message.<br>
<br>
What's the cause and is there a solution?<br>
<br>
<br>
<div style="font-family:Tahoma; font-size:13px">---
<div>Roberto Ullfig -&nbsp;ACCC Research Programmer<br>
<div>rullfig@uic.edu</div>
</div>
</div>
</div>
</div>
</body>
</html>