<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">On 2/4/16 4:56 PM, Liam Hoekenga wrote:<br>
    </div>
    <blockquote
cite="mid:CAH4ZtKRCdPVMhJRW9Hg83K_g4zAXEu8VAO521ifvBsSS+Q4F+w@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_extra">
          <div class="gmail_quote"><br>
            <div>My bad.  I like pretty printing.  Here's the
              un-altered..</div>
            <div><br>
            </div>
            <div><br>
            </div>
          </div>
        </div>
      </div>
    </blockquote>
    <br>
    That looks good.  I even threw that into a file and OpenSAML
    ParserPool can parse just fine.  So if that's literally the entirety
    of the request body, it ought to work...<br>
    <br>
    <blockquote
cite="mid:CAH4ZtKRCdPVMhJRW9Hg83K_g4zAXEu8VAO521ifvBsSS+Q4F+w@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_extra">
          <div class="gmail_quote">
            <div> <br>
            </div>
          </div>
          As downloaded, it does use the wrong content type.  I took a
          hint from John Dennis's message and added </div>
        <div class="gmail_extra">-H "Content-Type: text/xml;
          charset=utf-8"<br>
        </div>
        <div class="gmail_extra"><br>
        </div>
        <div class="gmail_extra">The unmodified script does use
          application/x-www-form-urlencoded.  The SOAP request looks the
          same...</div>
      </div>
    </blockquote>
    <br>
    Ah, ok.  That makes more sense.<br>
    <br>
    <br>
    <blockquote
cite="mid:CAH4ZtKRCdPVMhJRW9Hg83K_g4zAXEu8VAO521ifvBsSS+Q4F+w@mail.gmail.com"
      type="cite">
      <div dir="ltr"><br>
        <div class="gmail_extra">The headers look the same, save the
          content-type...</div>
        <div class="gmail_extra">
          <div class="gmail_extra">> POST /idp/profile/SAML2/SOAP/ECP
            HTTP/1.1</div>
          <div class="gmail_extra">> Host: <a moz-do-not-send="true"
              href="http://shib-idp-test.www.umich.edu">shib-idp-test.www.umich.edu</a></div>
          <div class="gmail_extra">> User-Agent: curl/7.46.0</div>
          <div class="gmail_extra">> Accept: */*</div>
          <div class="gmail_extra">> Authorization: Basic
            *************************</div>
          <div class="gmail_extra">> Content-Length: 735</div>
          <div class="gmail_extra">> Content-Type:
            application/x-www-form-urlencoded</div>
          <div class="gmail_extra"><br>
          </div>
        </div>
        <div class="gmail_extra">...and both content types result in the
          IdP throwing a 500 (tho maybe for different reasons?)<br>
        </div>
      </div>
      <br>
    </blockquote>
    <br>
    <br>
    Yeah, so with the right content type, does the IdP still log the
    same XML parsing error?  If so, I'm at a loss.  Need to confirm, b/c
    it's entirely possible that it's getting past the parsing but then
    throwing a fatal error which results in the 500 and SOAP fault you
    previously posted, for example something specific to the authN or
    ECP case.  For example, not sure off-hand what that would return if
    for example basic authN isn't configured correctly and so there's no
    REMOTE_USER visible in the request. <br>
    <br>
    <br>
  </body>
</html>