<div dir="ltr"><div>I’m seeing a pattern of paired requests, the first of which appears to end this way:<br><br>08:24:04.368 - DEBUG [org.opensaml.saml2.metadata.support.AttributeConsumingServiceSelector:186] - Resolving AttributeConsumingService candidates from SPSSODescriptor<br>08:24:04.368 - DEBUG [org.opensaml.saml2.metadata.support.AttributeConsumingServiceSelector:141] - AttributeConsumingService candidate list was empty, can not select service<br>08:24:04.369 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:832] - Redirecting to login page [/login.jsp]<br>08:24:04.369 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:499] - submodule returned [true]<br><br>The second of the pair of requests is typically about 20 or 30 seconds later from the same IP, and proceeds normally through authentication, attribute resolution and issuing a SAML assertion.<br><br>I’m presuming that means the IdP bailed prior even to authentication on the first request because it does not know where to send the SAML assertion - yes?<br><br>I’m thrice removed from the end users for this SP unfortunately.  What would you expect the user experience to be - what will be displayed in their browser as a result?<br><br>Have you seen an SP behave this way or have a suggestion of what it might be doing?  Or is this down to end user behavior?<br><br>Thanks for any insight.<br><br><br></div>David Bantz<br>U Alaska<br><div><br></div></div>