<html><head><style>body{font-family:Helvetica,Arial;font-size:13px}</style></head><body style="word-wrap:break-word;line-break:after-white-space"><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px;color:rgba(0,0,0,1.0);margin:0px;line-height:auto"><br></div> <br> <div id="bloop_sign_1520983756543903744" class="bloop_sign"></div> <br><p class="airmail_on">On March 13, 2018 at 5:39:07 PM, Cantor, Scott (<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>) wrote:</p> <div><blockquote type="cite" class="clean_bq" style="font-family:Helvetica,Arial;font-size:13px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"><span><div><div></div><div>> Bummer. I was sort of hoping to fix their metadata so that I could move the<span class="Apple-converted-space"> </span><br>> project along. Thanks, anyway, Scott.<span class="Apple-converted-space"> </span><br><br>They aren't using metadata to begin with, obviously, or it would be working. I don't really understand what you think is happening, but I assume they manually pointed at a SAML 1 legacy endpoint, that's all. It's going to /idp/profile/Shibboleth/SSO I would assume.<span class="Apple-converted-space"> </span></div></div></span></blockquote></div><p>I thought, from what you said, that once I successfully authenticated, they were redirecting me to a different AssertionConsumerService location, than the one in their metadata (in my mind, I associate that value with an endpoint). Since the two “endpoints” were different, the Authentication Request could not be decoded. It never occurred to me that you were talking about my (IdP) endpoint. I think I understand now. Is there any way to confirm that they are going to the SAML 1 legacy endpoint?</p><p><br></p><p>Thanks,</p><p>Mike</p></body></html>