<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Feb 5, 2016 at 12:01 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><div id=":5yp" class="" style="overflow:hidden">Those are all DEBUG messages. If there's nothing on INFO, that's a problem.<br></div></blockquote><div><br></div><div>The only INFO generated by that transaction is..</div><div>2016-02-05 15:33:34,567 - INFO [Shibboleth-Audit.SSO:241] - xxx.xxx.xxx.xxx - 20160205T203334Z|urn:oasis:names:tc:SAML:2.0:bindings:SOAP|_B9228743684D4D4FB9B4C4439D4D15D1|urn:amazon:webservices|<a href="http://shibboleth.net/ns/profiles/saml2/sso/ecp|https://shib-idp-test.www.umich.edu/idp/shibboleth|||||||">http://shibboleth.net/ns/profiles/saml2/sso/ecp|https://shib-idp-test.www.umich.edu/idp/shibboleth|||||||</a></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><div id=":5yp" class="" style="overflow:hidden">
The trigger for this is specifying an ACS with a non-PAOS binding?</div></blockquote></div><br>Yessir.</div><div class="gmail_extra"><br></div><div class="gmail_extra"><div class="gmail_extra"><S:Envelope xmlns:S="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"></div><div class="gmail_extra"> <S:Body></div><div class="gmail_extra"> <samlp:AuthnRequest</div><div class="gmail_extra"> AssertionConsumerServiceURL="<a href="https://signin.aws.amazon.com/saml">https://signin.aws.amazon.com/saml</a>"</div><div class="gmail_extra"> ID="_B9228743684D4D4FB9B4C4439D4D15D1"</div><div class="gmail_extra"> IssueInstant="2016-02-05T20:33:44"</div><div class="gmail_extra"> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</div><div class="gmail_extra"> Version="2.0" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"></div><div class="gmail_extra"> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:amazon:webservices</saml:Issuer></div><div class="gmail_extra"> <samlp:NameIDPolicy AllowCreate="1"/></div><div class="gmail_extra"> <samlp:Scoping></div><div class="gmail_extra"> <samlp:IDPList></div><div class="gmail_extra"> <samlp:IDPEntry ProviderID="<a href="https://shib-idp-test.www.umich.edu/idp/shibboleth">https://shib-idp-test.www.umich.edu/idp/shibboleth</a>"/></div><div class="gmail_extra"> </samlp:IDPList></div><div class="gmail_extra"> </samlp:Scoping></div><div class="gmail_extra"> </samlp:AuthnRequest></div><div class="gmail_extra"> </S:Body></div><div class="gmail_extra"></S:Envelope></div></div></div>