<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <div class="moz-cite-prefix">On 11/10/16 10:42 AM, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote
cite="mid:9846A6064BD102419D06814DD0D78DE112A8D115@CIO-TNC-D2MBX02.osuad.osu.edu"
      type="cite">
      <blockquote type="cite">
        <pre wrap="">After a short research I found that the IE11 support around 2000 character in
the URL. The URL with the AuthRequest has more than 2000 characters.
</pre>
      </blockquote>
      <pre wrap="">
I haven't really every seen anything that long. If this isn't Shibboleth, then I would probably suspect that SP is broken in some way.</pre>
    </blockquote>
    <blockquote
cite="mid:9846A6064BD102419D06814DD0D78DE112A8D115@CIO-TNC-D2MBX02.osuad.osu.edu"
      type="cite">
    </blockquote>
    <br>
    That does seem a bit large.  I think the obvious initial suspicion
    is that the SP might be incorrectly sending via the Redirect binding
    the AuthnRequest signed at the XML level rather than using the
    (required) binding signature mechanism.  That's the only obvious
    thing I can think of.  <br>
    <br>
    Unlikely, but maybe could be some huge number of extensions and/or
    extension data (or Conditions, but that seems even less likely).<br>
  </body>
</html>