<div dir="ltr">Vendor's SP is sending the following SAML request (according to them):<div><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> ID="s25d6fccde9c929700b616acf6e3c291122f61a844"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> Version="2.0"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> IssueInstant="2015-06-25T21:13:50Z"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> Destination="<a href="https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO" target="_blank">https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO</a>"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> ForceAuthn="true"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> IsPassive="false"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> AssertionConsumerServiceURL="<a href="https://sso.uat.firstmarblehead.com/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp" target="_blank">https://sso.uat.firstmarblehead.<span class="">com</span>/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp</a>"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> ><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso" target="_blank">sso.uat.firstmarblehead.<span class="">com</span>/uaaalaska_sso</a></saml:Issuer><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> <samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> SPNameQualifier="<a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso" target="_blank">sso.uat.firstmarblehead.<span class="">com</span>/uaaalaska_sso</a>"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> AllowCreate="true"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> /><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> <samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> Comparison="exact"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> ><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"> </samlp:RequestedAuthnContext><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"></samlp:AuthnRequest></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"><br></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt"><font face="arial, helvetica, sans-serif"><span style="font-size:13.3333330154419px">which seems to verify Brent's diagnosis (POST request sent to Redirect end point). Is there any other obvious problem with the request I could point out and save a week's turnaround with the vendor technical staff? Thanks!</span></font></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt"><font face="arial, helvetica, sans-serif"><span style="font-size:13.3333330154419px"><br></span></font></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt"><font face="arial, helvetica, sans-serif"><span style="font-size:13.3333330154419px">David</span></font></p></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jun 23, 2015 at 5:19 PM, Brent Putman <span dir="ltr"><<a href="mailto:putmanb@georgetown.edu" target="_blank">putmanb@georgetown.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="#FFFFFF" text="#000000"><span class="">
<br>
<br>
<div>On 6/23/15 8:45 PM, IAM David Bantz
wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr"><br>
<div>
<p><span>12:37:43.141 - WARN
[edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:400]
- <br>
Error decoding authentication
request message </span>org.opensaml.ws.message.decoder.MessageDecodingException:
<br>
No SAMLRequest or SAMLResponse query
path parameter, invalid SAML 2 HTTP Redirect message</p>
</div>
</div>
</blockquote>
<br>
<br></span>
I don't think this has anything to do with the other stuff you
mentioned. They are simply not sending a valid SAML 2 Redirect
binding request. Most likely they are doing the POST binding, but
mistakenly sending it to the IdP's Redirect endpoint. Just change
the binding or the endpoint in use.<br>
<br>
If that's not it, then the message means what it says: there's
literally not a query parameter called in SAMLRequest in the HTTP
request to the IdP. You should be able to see exactly what they are
sending in your browser, possibly using Firefox Live Headers or SAML
Tracer.<br>
<br>
All the other stuff you mentioned re: the MCB, authN contexts, etc,
is not related to the above error.<br>
<br>
</div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div></div>