<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;"><div>I got a question from helpdesk on our test IdP.</div><div><br></div><div>They are asking why they get a “Requester” error status code when the underlying reason is AuthnFailed.</div><div><br></div><div><div>    <saml2p:Status></div><div>        <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester"></div><div>            <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/></div><div>        </saml2p:StatusCode></div><div>        <saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage></div><div>    </saml2p:Status></div></div><div><br></div><div><br></div><div>This seems to be the default configuration in error.xml</div><div><br></div><div>Why is it so?</div><div>The major status code seems to propose that there is an error on behalf of the requester, which clearly is not the case.</div><div><br></div><div>Is it safe to reconfigure this, or can this create other problems?</div><div><br></div><div>/Stefan</div><div><br></div><div><br></div><span id="OLK_SRC_BODY_SECTION"><blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;"></blockquote></span></body></html>