<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><div>After successful authN and SAML response to a vendor SP, the SP disregards the attributes, immediately issuing the following attribute query using the (correct) transient ID sent in the first response:</div><div><br></div><div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">15:23:35.546 - DEBUG [PROTOCOL_MESSAGE:113] -&nbsp;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&lt;?xml version="1.0" encoding="UTF-8"?&gt;&lt;SOAP-ENV:Envelope xmlns:SOAP-ENV="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &lt;SOAP-ENV:Body&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &lt;samlp:AttributeQuery xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Destination="<a href="https://howkan.alaska.edu/idp/profile/SAML2/SOAP/AttributeQuery">https://howkan.alaska.edu/idp/profile/SAML2/SOAP/AttributeQuery</a>" ID="_E6F1CF2094EFD85C586B0D8CD0329282" IssueInstant="2014-10-22T23:23:35Z" Version="2.0"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"&gt;<a href="https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt&lt;/saml:Issuer&gt;">https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt&lt;/saml:Issuer&gt;</a></div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;Signature xmlns="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SignedInfo&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SignatureMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Reference URI="#_E6F1CF2094EFD85C586B0D8CD0329282"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Transforms&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;InclusiveNamespaces xmlns="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>" PrefixList="#default saml ds xs xsi"/&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/Transform&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/Transforms&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;DigestValue&gt;tAShZ+t+fHp3JdnLtUPjWp1M1bM=&lt;/DigestValue&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/Reference&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/SignedInfo&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SignatureValue&gt;Tdxbes8Tb5wIOC3tarmg79ZPGtBJXROxoyLwT4AdDXatqLOZL2l8N8QBNlExoIhgWaL0mpGWT847yZvFYNr8oe7adiJ2JlIA4xoNI159xzdr9DJ7D1KjM0k2XtqiObZZM+kFSMW0Q6I2Hhc8ku6+GqF4ZZxP94aWKcpn5WVCxozphzU+XwOCAmJwoNwnCVsROI8aukJFT4Mn9/+jdXwo/3YUqAHIRuESACVNuaDME7mzmycQJyl63o4OmSVpphR+gqe/Eec/of9twy2W/vBmfCZBwfFNjryR7ZYdnpCV+Usq+jTx+jjfbhyu4oJdL5oleyPw7zzxWh5j6DeF0sSiBg==&lt;/SignatureValue&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;KeyInfo&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;X509Data&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;X509Certificate&gt;...&lt;/X509Certificate&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/X509Data&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/KeyInfo&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;/Signature&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml:Subject xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="urn:mace:incommon:alaska.edu" SPNameQualifier="<a href="https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt">https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt</a>"&gt;_8e5887f31d16ec94f0dffb69c75b6213&lt;/saml:NameID&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml:Subject&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &lt;/samlp:AttributeQuery&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &lt;/SOAP-ENV:Body&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&lt;/SOAP-ENV:Envelope&gt;</div></div><div><br></div><div>My IdP logs show the following WARN:</div><div><br></div><div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.AttributeQueryProfileHandler:95] - SAML 2 Attribute Query profile is not configured for relying party org.opensaml.ws.soap.soap11.impl.EnvelopeImpl@2af94feb</div></div><div><br></div><div>And then issues a corresponding SAML response:</div><div><br></div><div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">DEBUG [PROTOCOL_MESSAGE:74] -&nbsp;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&lt;?xml version="1.0" encoding="UTF-8"?&gt;&lt;soap11:Envelope xmlns:soap11="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &lt;soap11:Body&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &lt;saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" ID="_f0faf266e14efe840ba8f2a25a32b313" InResponseTo="_E6F1CF2094EFD85C586B0D8CD0329282" IssueInstant="2014-10-22T23:23:35.550Z" Version="2.0"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"&gt;urn:mace:incommon:alaska.edu&lt;/saml2:Issuer&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2p:Status&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder"&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:RequestDenied"/&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2p:StatusCode&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2p:StatusMessage&gt;SAML 2 Attribute Query profile is not configured for relying party org.opensaml.ws.soap.soap11.impl.EnvelopeImpl@2af94feb&lt;/saml2p:StatusMessage&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &lt;/saml2p:Status&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp; &nbsp; &nbsp; &lt;/saml2p:Response&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&nbsp;&nbsp; &lt;/soap11:Body&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">&lt;/soap11:Envelope&gt;</div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); min-height: 16px; position: static; z-index: auto;"><br></div></div><div><br></div><div><div style="font-size: 14px;">It’s certainly true that there is no such relying party as&nbsp;<span style="background-color: rgb(255, 250, 194); font-family: Monaco;">org.opensaml.ws.soap.soap11.impl.EnvelopeImpl@2af94feb in my configuration</span>. &nbsp;</div><div style="font-size: 14px;">Should there be? &nbsp;Where did that relying party name come from?</div></div><div></div><div></div></body></html>