<div dir="ltr">Hi,<div><br></div><div>I've done some searching around and have not had luck finding anything about this. We're running Apache 2.2 + Shibd 2.5.3, and it was running fine in my test environment until I started trying to integrate with a Tivoli IdP<br clear="all"><div><br></div><div>When we try to redirect to the Tivoli system to allow the user to authenticate there (and get an assertion back from the IdP, we get:</div><div><br></div><div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">Log Name: Application<br>Source: Application Error<br>Date: 8/17/2015 2:57:01 PM<br>Event ID: 1000<br>Task Category: (100)<br>Level: Error<br>Keywords: Classic<br>User: N/A<br>Computer: x<br>Description:<br>Faulting application name: shibd.exe, version: 2.5.3.0, time stamp: 0x5296b0dd<br>Faulting module name: xsec_1_7.dll, version: 1.7.1.0, time stamp: 0x51a01390<br>Exception code: 0xc0000005<br>Fault offset: 0x000089a4<br>Faulting process id: 0x6c8<br>Faulting application start time: 0x01d0d91e688c645f<br>Faulting application path: C:\program files\shibboleth-sp\sbin\shibd.exe<br>Faulting module path: C:\Program Files (x86)\Shibboleth\SP\lib\xsec_1_7.dll<br>Report Id: bdd4dc28-4511-11e5-b45d-005056853679<br></blockquote><div><br></div></div><div>Relevant (sanitized) section shibd.log:</div><div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">2015-08-17 14:57:01 DEBUG Shibboleth.Listener [1]: dispatching message (ts/Login::run::SAML2SI)<br>2015-08-17 14:57:01 DEBUG XMLTooling.StorageService [1]: inserted record (a15d98535b5d44171f13a9193ac9d57e7c6e9fe51cab67803edb772c2b4430fa) in context (RelayState) with expiration (1439838421)<br>2015-08-17 14:57:01 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: validating input<br>2015-08-17 14:57:01 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: marshalling, deflating, base64-encoding the message<br>2015-08-17 14:57:01 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: marshalled message:<br><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://ts.host.com/Shibboleth.sso/SAML2/POST">https://ts.host.com/Shibboleth.sso/SAML2/POST</a>" Destination="<a href="https://otherhost/sps/SSFFed/saml20/login">https://otherhost/sps/SSFFed/saml20/login</a>" ID="_91220ac8878fefa15675facca0a60856" IssueInstant="2015-08-17T18:57:01Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://ts.host.com/shibboleth">https://ts.host.com/shibboleth</a></saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest><br>2015-08-17 14:57:01 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: signing the message</blockquote></div><div><br></div><div>...and then, crash.</div><div><br></div><div>Where else can I look for what might be causing this? Misconfiguration? Bug? </div><div><br></div><div>Thanks!</div>-- <br><div class="gmail_signature"><div dir="ltr"><div><font face="'courier new', monospace">jerry b. altzman <a href="mailto:jbaltz@gmail.com" target="_blank">jbaltz@gmail.com</a> </font><span style="font-family:'courier new',monospace;font-size:12.8000001907349px">@lorvax </span><font face="'courier new', monospace"><br>eppur si muove <br></font></div></div></div>
</div></div>