<div dir="ltr">Hello list,<div><br></div><div>I&#39;m trying to get the SAML SP support in our helpdesk app to work with a TestShib IdP.</div><div><br></div><div>Our app is known to work with some SAML IdP implementations, but I can&#39;t work out the correct settings to use with TestShib.</div><div><br></div><div>The SP has settings for SSO URL, SLO URL, Issuer Metadata URL, X509 cert.</div><div><br></div><div>Based on looking at the info in testshib-providers.xml I have tried various SSO URLs and they return different errors:</div><div><br></div><div><div><br></div><div>Using</div><div><a href="https://idp.testshib.org/idp/profile/Shibboleth/SSO">https://idp.testshib.org/idp/profile/Shibboleth/SSO</a></div><div>Error Message: Error decoding Shibboleth SSO request<br></div><div><br></div><div>Using <a href="https://idp.testshib.org/idp/profile/SAML2/Redirect/SSO">https://idp.testshib.org/idp/profile/SAML2/Redirect/SSO</a></div><div>Error Message: SAML 2 SSO profile is not configured for relying party <a href="http://192.241.188.182/saml/metadata/9.xml">http://192.241.188.182/saml/metadata/9.xml</a><br></div><div><br></div><div>Using <a href="https://idp.testshib.org/idp/profile/SAML2/POST/SSO">https://idp.testshib.org/idp/profile/SAML2/POST/SSO</a><br></div><div>Error Message: Error decoding authentication request message<br></div></div><div><br></div><div><br></div><div>What would cause these errors? I have entered the X509 cert from the issuer metadata.</div><div><br></div><div>Is our SP implementation not providing some needed value?</div><div><br></div><div>Thanks,</div><div><br></div><div>Ben</div></div>