<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman",serif;
color:black;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";
color:black;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;
color:black;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks Brent,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I will apply all of that, and see what I can find out.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks again.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">-Josh<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> users [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Brent Putman<br>
<b>Sent:</b> Friday, August 25, 2017 12:11 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Troubleshooting the "Unable to decode" (IdP 3.3)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">On 8/25/17 1:20 PM, O'Dowd, Josh wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<pre>Actually, there is a SAMLRequest parameter that I missed, coming after the RelayState parameter, and now I see that only some of the failed requests have a leading RelayState parameter.<o:p></o:p></pre>
<pre>Sample access entry for failed request:<o:p></o:p></pre>
<pre>[25/Aug/2017:09:24:05 -0600] TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 "GET /idp/profile/SAML2/Redirect/SLO?RelayState=ss:m<o:p></o:p></pre>
<pre>em:18e8f777deec8579d5adfb48fbaf6d9ae296df30c777408c7058488b5509bd70&SAMLRequest=rVbJcqNIEL3rKxzqo8JmEwIUtiNYtLFoAyTBZaIExSKxiSoE6OsHd<o:p></o:p></pre>
<pre>dvT7e6ZCffEXLMyX+Z7mUnyjECaFGM9D/MKb+Glggg/NGmSofHXl5d+VWbjHKAYjTOQQjTG3tgUDX1MP5Hjosxx7uVJ/0Hp4uIM4DjPXvoRxgUaE0SSh3H2VKX4CfoVEfsF0Q<o:p></o:p></pre>
<pre>...<o:p></o:p></pre>
<pre>...<o:p></o:p></pre>
<pre>83szyP7Zvz5rr2fWBOi++VbZD5sXv+gu9+EI8OwggcBF7AM4I40oASK5T0B+EHwfjE/RL0bP/wBvf4J&SigAlg=<a href="http://www.w3.org/2000/09/xmldsig">http://www.w3.org/2000/09/xmldsig</a> HTTP/1.1" 40<o:p></o:p></pre>
<pre>0 18603<o:p></o:p></pre>
</blockquote>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
<br>
With the full request URL, specifically the SAMLRequest param (which is the actual SAML protocol message), you can try decoding that with one of the online SAML decoder/debugger services. I have used in the past:<br>
<br>
<a href="https://rnd.feide.no/software/saml_2_0_debugger/">https://rnd.feide.no/software/saml_2_0_debugger/</a><br>
<br>
<br>
Also just found some others via googling, such as:<br>
<br>
<a href="https://www.samltool.com/decode.php">https://www.samltool.com/decode.php</a><br>
<br>
<br>
I'll be a little surprised if those can decode them though, and OpenSAML can't, at least for valid inputs. The OpenSAML code has essentially been in use for over a decade, and is not known to have any issues with valid requests.<br>
<br>
Since this is the Redirect binding, what I would initially suspect is that they aren't encoded properly, wrt to the Deflate part, i.e. maybe it's just Base64-encoded and not Deflated. That's not valid Redirect binding and OpenSAML would not handle and would
treat as an error. A decoder tool that attempts to dynamically support Redirect and POST input simultaneously might be less strict. (I think the FEIDE one does that). You could also try just handing the SAMLRequest value to a Base64 decoder and see what
happens. If it works, then they aren't deflating.<br>
<br>
<br>
<br>
<br>
<br>
<o:p></o:p></p>
</div>
</body>
</html>