<div dir="ltr">Vendor's SP is sending the following SAML request (according to them):<div><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    ID="s25d6fccde9c929700b616acf6e3c291122f61a844"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    Version="2.0"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    IssueInstant="2015-06-25T21:13:50Z"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    Destination="<a href="https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO" target="_blank">https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO</a>"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    ForceAuthn="true"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    IsPassive="false"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    AssertionConsumerServiceURL="<a href="https://sso.uat.firstmarblehead.com/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp" target="_blank">https://sso.uat.firstmarblehead.<span class="">com</span>/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp</a>"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                    ><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">    <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso" target="_blank">sso.uat.firstmarblehead.<span class="">com</span>/uaaalaska_sso</a></saml:Issuer><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">    <samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                        Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                        SPNameQualifier="<a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso" target="_blank">sso.uat.firstmarblehead.<span class="">com</span>/uaaalaska_sso</a>"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                        AllowCreate="true"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                        /><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">    <samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                                 Comparison="exact"<u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">                                 ><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">        <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'">    </samlp:RequestedAuthnContext><u></u><u></u></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"></samlp:AuthnRequest></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt;font-size:12pt;font-family:'Times New Roman',serif"><span style="font-size:10pt;font-family:'Courier New'"><br></span></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt"><font face="arial, helvetica, sans-serif"><span style="font-size:13.3333330154419px">which seems to verify Brent's diagnosis (POST request sent to Redirect end point).  Is there any other obvious problem with the request I could point out and save a week's turnaround with the vendor technical staff?  Thanks!</span></font></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt"><font face="arial, helvetica, sans-serif"><span style="font-size:13.3333330154419px"><br></span></font></p><p class="MsoNormal" style="margin:0in 0in 0.0001pt"><font face="arial, helvetica, sans-serif"><span style="font-size:13.3333330154419px">David</span></font></p></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jun 23, 2015 at 5:19 PM, Brent Putman <span dir="ltr"><<a href="mailto:putmanb@georgetown.edu" target="_blank">putmanb@georgetown.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
  
    
  
  <div bgcolor="#FFFFFF" text="#000000"><span class="">
    <br>
    <br>
    <div>On 6/23/15 8:45 PM, IAM David Bantz
      wrote:<br>
    </div>
    <blockquote type="cite">
      <div dir="ltr"><br>
        <div>
          <p><span>12:37:43.141 - WARN
              [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:400]
              - <br>
                                      Error decoding authentication
              request message </span>org.opensaml.ws.message.decoder.MessageDecodingException:
            <br>
                                    No SAMLRequest or SAMLResponse query
            path parameter, invalid SAML 2 HTTP Redirect message</p>
        </div>
      </div>
    </blockquote>
    <br>
    <br></span>
    I don't think this has anything to do with the other stuff you
    mentioned.  They are simply not sending a valid SAML 2 Redirect
    binding request.  Most likely they are doing the POST binding, but
    mistakenly sending it to the IdP's Redirect endpoint.  Just change
    the binding or the endpoint in use.<br>
    <br>
    If that's not it, then the message means what it says: there's
    literally not a query parameter called in SAMLRequest in the HTTP
    request to the IdP.  You should be able to see exactly what they are
    sending in your browser, possibly using Firefox Live Headers or SAML
    Tracer.<br>
    <br>
    All the other stuff you mentioned re: the MCB, authN contexts, etc,
    is not related to the above error.<br>
    <br>
  </div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div></div>