<div dir="ltr"><div><div><div><div>Scott:<br><br></div>You were absolutely correct ... including the endpoint URL.<br><br></div>(My apologies,  I realize you're not being paid to answer emails) Could you tell me what in my original problem description led you to believe that was the problem?  I'm asking to try and learn from my mistakes.<br><br></div>Thanks,<br></div>Mike<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Mar 13, 2018 at 7:45 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> I thought, from what you said, that once I successfully authenticated, they were<br>
> redirecting me to a different AssertionConsumerService location, than the one<br>
> in their metadata (in my mind, I associate that value with an endpoint).<br>
<br>
</span>Nope.<br>
<span class=""><br>
> Is there any way to confirm that they are going to the SAML 1 legacy endpoint?<br>
<br>
</span>IdP and web server logs. Audit logs. Pretty much every log in different ways.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>