<div dir="ltr"><p class="">still waiting on confirmation from IdP on RelayState settings. in the meantime I'm comparing the SAML2/POST contents of SP initited and IdP initiated and I can see that the referer in the IdP initiated case is missing the attributes ?SAMLRequest=... and &RelayState=... (whereas they exist in the SP initiated case)</p><p class="">will post again once more details have been uncovered.</p><p class="">thanks!</p><p class=""><br></p><p class="">On 12/18/14, 3:56 PM, "Luay Zakaria" <<a href="mailto:luay.zakaria@gmail.com">luay.zakaria@gmail.com</a>> wrote:</p>
<p class=""> </p>
<p class="">>Actually, shibd.log is showing a successful session
being created:</p>
<p class="">>2014-12-18 10:07:09 INFO Shibboleth.SessionCache [1]:
new session</p>
<p class="">>created: ID (_ce47b311a1f489cb3fef260f38841a80) IdP</p>
<p class="">>(<a href="http://sts.someIDP.com/adfs/services/trust">http://sts.someIDP.com/adfs/services/trust</a>)</p>
<p class="">>Protocol(urn:oasis:names:tc:SAML:2.0:protocol)</p>
<p class="">> Address (....)</p>
<p class="">>Transaction.log is showing a matching session
successfully created as </p>
<p class="">>well.</p>
<p class="">>At the sametime, native_warn.log is showing the
error:</p>
<p class="">>2014-12-18 10:07:09 ERROR Shibboleth.ISAPI [14180]
isapi_shib_extension: </p>
<p class="">>URL is malformed.</p>
<p class=""> </p>
<p class="">Then my guess would be that the RelayState is invalid and
it's trying to use it as a URL to redirect to, subsequently flagging it.</p>
<p class=""> </p>
<p class="">Tom already suggested that, and I saw no follow up.</p>
<p class=""> </p>
<p class="">-- Scott</p>
<p class=""> </p>
<p class="">--</p>
<p class="">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></p></div>