<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">On 8/14/15 3:04 PM, Brent Putman wrote:<br>
    </div>
    <blockquote cite="mid:55CE3BC2.80001@georgetown.edu" type="cite">
      <meta content="text/html; charset=windows-1252"
        http-equiv="Content-Type">
      <br>
      <br>
      Just to be clear here:  That AuthnRequest XML there is NOT what is
      in the AuthnRequest in the Redirect binding above after it's
      decoded (i.e. it's not myserver.com).<br>
    </blockquote>
    <br>
    In fact it's not just the request issuer entityID that's different,
    it's other things like the request Destination and ACS URL.  Were
    you deliberately obfuscating all of that in what you've been
    posting?<br>
    <br>
    <blockquote cite="mid:55CE3BC2.80001@georgetown.edu" type="cite"> <br>
      <br>
      OTOH, if you're saying that the issued Assertion literally
      contains as audience the string <a moz-do-not-send="true"
        class="moz-txt-link-rfc2396E" href="https://myserver.com">"https://myserver.com"</a>,
      then I have no idea what's going on, since that's not what's in
      the actual AuthnRequest above (and have no idea how/where you got
      that 2nd XML snippet). <br>
    </blockquote>
    <br>
    If you're not obfuscating, then based on some of the names in the
    first decoded AuthnRequest: is there some sort of SAML proxying
    going on there?  Is so, then that is probably the source of the
    issue.<br>
  </body>
</html>