<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">On 8/14/15 4:58 PM, Scott Gerlach
      wrote:<br>
    </div>
    <blockquote
cite="mid:CAEDuAAojZf=GKjOCLRy0Dxq-8muzFgH+CP7NeUEsuP4Rjq84jQ@mail.gmail.com"
      type="cite">
      <div dir="ltr"><br>
        <div class="gmail_extra">
          <div class="gmail_quote">
            <blockquote class="gmail_quote" style="margin:0 0 0
              .8ex;border-left:1px #ccc solid;padding-left:1ex">
              <div bgcolor="#FFFFFF" text="#000000">>In fact it's not
                just the request issuer entityID that's different, it's
                other things like the request Destination and ACS URL. 
                Were you deliberately obfuscating all of that in what
                you've been posting?</div>
            </blockquote>
            <div>I was, and failed miserably ultimately :$
              (encoding/deflate got me on that one, I knew that was
              gonna happen...). The replaced strings are find/replace
              for actual servername, acs url, and destination and not
              hand replaced. I have closely checked the request and
              responses and they are not mispelled or mis-capitalized.<br>
            </div>
          </div>
        </div>
      </div>
    </blockquote>
    <br>
    Ok.  Well, again, just to be clear:  You're saying that in the
    actual messages that you trace, the AuthnRequest Issuer element
    value matches *exactly*, character for character, what's in the
    issued Assertion's Audience element value?<br>
    <br>
    If so, I really have no explanation.<br>
    <br>
    <br>
  </body>
</html>