<div dir="ltr">To recap, vendor's SAML request was triggering the IdP to report back that authentication failed (even though the the user-submitted credentials bound to LDAP). <br>Brent Putman correcty divined that the vendor's SAML request sent a POST message to the Redirect end point.<div><br></div><div>BUT the vendor insists they have configured "40 plus" institutions this way and cannot readily change either the destination to POST/SSO or change the binding to Redirect.</div><div>In discussion, they invoked the name "Scott Cantor" as having worked with them on their first Shibboleth integration that set up this configuration. I'm just reporting!</div><div><br></div><div>In any case, SOME change was made at the vendor end and my IdP is now provides a SAML response to their request (at least it responds for my account using MCB/Duo MFA). Yet, as I can verify directly, the SAML POST request is still sent to the IdP's Redirect end point. Surprisingly (to me) the IdP doesn't trigger any warnings about this, and provides an affirmative SAML response confirming authentication and including attributes. </div><div><br></div><div>If it doesn't matter where the request is sent, why do we bother with the different end points? If it matters, will this fail under some as-yet-untested circumstances?</div><div><br></div><div>David Bantz</div><div><br></div><div>Here's the latest SAML request I captured in SAML Tracer:</div><div><div class="gmail_extra"><br><div class="gmail_quote"><pre id="txt"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
ID="s26c8d71ee6f9c431b5472159becb07099bee19e8b"
Version="2.0"
IssueInstant="2015-07-06T23:43:47Z"
Destination="<a href="https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO">https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO</a>"
ForceAuthn="true"
IsPassive="false"
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
AssertionConsumerServiceURL="<a href="https://sso.uat.firstmarblehead.com/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp">https://sso.uat.firstmarblehead.com/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp</a>"
>
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso">sso.uat.firstmarblehead.com/uaaalaska_sso</a></saml:Issuer>
<samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
SPNameQualifier="<a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso">sso.uat.firstmarblehead.com/uaaalaska_sso</a>"
AllowCreate="true"
/>
<samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
Comparison="exact"
>
<saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef>
</samlp:RequestedAuthnContext>
</samlp:AuthnRequest></pre><pre id="txt"><font face="arial, helvetica, sans-serif">and the SAML response from the IdP logs (minus the signature):</font></pre><pre id="txt"><?xml version="1.0" encoding="UTF-8"?><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_f9ce79b9284aa8f5af748967b30c7bd0" IssueInstant="2015-07-06T23:44:07.385Z" Version="2.0" xmlns:xs="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>">
<saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:<a href="http://alaska.edu">alaska.edu</a></saml2:Issuer>
<ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/>
<ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/>
<ds:Reference URI="#_f9ce79b9284aa8f5af748967b30c7bd0">
<ds:Transforms>
<ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/>
<ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>">
<ec:InclusiveNamespaces xmlns:ec="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>" PrefixList="xs"/>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/>
<ds:DigestValue>i86bF26dCP7Tq4dRn0v43q0NtFI=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
…
<saml2:Subject>
<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="urn:mace:incommon:<a href="http://alaska.edu">alaska.edu</a>" SPNameQualifier="<a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso">sso.uat.firstmarblehead.com/uaaalaska_sso</a>"><a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a></saml2:NameID>
<saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<saml2:SubjectConfirmationData Address="137.229.112.75" InResponseTo="s26c8d71ee6f9c431b5472159becb07099bee19e8b" NotOnOrAfter="2015-07-06T23:49:07.385Z" Recipient="<a href="https://sso.uat.firstmarblehead.com/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp">https://sso.uat.firstmarblehead.com/openam/Consumer/metaAlias/fmdrealm001/uaaalaska_sso_sp</a>"/>
</saml2:SubjectConfirmation>
</saml2:Subject>
<saml2:Conditions NotBefore="2015-07-06T23:44:07.385Z" NotOnOrAfter="2015-07-06T23:49:07.385Z">
<saml2:AudienceRestriction>
<saml2:Audience><a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso">sso.uat.firstmarblehead.com/uaaalaska_sso</a></saml2:Audience>
</saml2:AudienceRestriction>
</saml2:Conditions>
<saml2:AuthnStatement AuthnInstant="2015-07-06T23:44:07.048Z" SessionIndex="_2438c11c5b07018ba88e1e3d19232c33">
<saml2:SubjectLocality Address="137.229.112.75"/>
<saml2:AuthnContext>
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
</saml2:AuthnStatement>
<saml2:AttributeStatement>
<saml2:Attribute FriendlyName="LastName" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">Bantz</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="bannerID" Name="<a href="https://iam.alaska.edu/trac/wiki/IamUaArp#bannerID">https://iam.alaska.edu/trac/wiki/IamUaArp#bannerID</a>" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">30459959</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string"><a href="mailto:db@alaska.edu">db@alaska.edu</a></saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="FirstName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">David</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="uaUsername" Name="<a href="https://iam.alaska.edu/trac/wiki/IamUaArp#uaUsername">https://iam.alaska.edu/trac/wiki/IamUaArp#uaUsername</a>" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">dabantz</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue>
<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="urn:mace:incommon:<a href="http://alaska.edu">alaska.edu</a>" SPNameQualifier="<a href="http://sso.uat.firstmarblehead.com/uaaalaska_sso">sso.uat.firstmarblehead.com/uaaalaska_sso</a>">w2t6APTZ8vM0zKQ3okPodI3pX4c=</saml2:NameID>
</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="username" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string"><a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a></saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="employeeNumber" Name="urn:oid:2.16.840.1.113730.3.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">30459959</saml2:AttributeValue>
</saml2:Attribute>
<saml2:Attribute FriendlyName="displayname" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string">David Bantz</saml2:AttributeValue>
</saml2:Attribute>
</saml2:AttributeStatement><br></pre></div></div></div></div>