<div dir="ltr"><p class="">still waiting on confirmation from IdP on RelayState settings. in the meantime I&#39;m comparing the SAML2/POST contents of SP initited and IdP initiated and I can see that the referer in the IdP initiated case is missing the attributes ?SAMLRequest=...   and   &amp;RelayState=...    (whereas they exist in the SP initiated case)</p><p class="">will post again once more details have been uncovered.</p><p class="">thanks!</p><p class=""><br></p><p class="">On 12/18/14, 3:56 PM, &quot;Luay Zakaria&quot; &lt;<a href="mailto:luay.zakaria@gmail.com">luay.zakaria@gmail.com</a>&gt; wrote:</p>

<p class=""> </p>

<p class="">&gt;Actually, shibd.log is showing a successful session
being created:</p>

<p class="">&gt;2014-12-18 10:07:09 INFO Shibboleth.SessionCache [1]:
new session</p>

<p class="">&gt;created: ID (_ce47b311a1f489cb3fef260f38841a80) IdP</p>

<p class="">&gt;(<a href="http://sts.someIDP.com/adfs/services/trust">http://sts.someIDP.com/adfs/services/trust</a>)</p>

<p class="">&gt;Protocol(urn:oasis:names:tc:SAML:2.0:protocol)</p>

<p class="">&gt; Address (....)</p>

<p class="">&gt;Transaction.log is showing a matching session
successfully created as </p>

<p class="">&gt;well.</p>

<p class="">&gt;At the sametime, native_warn.log is showing the
error:</p>

<p class="">&gt;2014-12-18 10:07:09 ERROR Shibboleth.ISAPI [14180]
isapi_shib_extension: </p>

<p class="">&gt;URL is malformed.</p>

<p class=""> </p>

<p class="">Then my guess would be that the RelayState is invalid and
it&#39;s trying to use it as a URL to redirect to, subsequently flagging it.</p>

<p class=""> </p>

<p class="">Tom already suggested that, and I saw no follow up.</p>

<p class=""> </p>

<p class="">-- Scott</p>

<p class=""> </p>

<p class="">--</p>

<p class="">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></p></div>