<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div class=""><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div style="color: rgb(0, 0, 0); font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; margin: 0in 0in 0.0001pt;" class="">Thanks Rod</div><div style="color: rgb(0, 0, 0); font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; margin: 0in 0in 0.0001pt;" class=""><br class=""></div></div></div></div></div></div></div></div></div></div><div><blockquote type="cite" class=""><div class="">On Jan 22, 2021, at 7:35 AM, Rod Widdowson <<a href="mailto:rdw@steadingsoftware.com" class="">rdw@steadingsoftware.com</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class=""><blockquote type="cite" class="">Then there really isn't any doubt, nor any doubt that IIS is so broken that it apparently doesn't honor the setting you're trying to<br class="">change, or has some inherent limitation that overrides the setting.<br class=""></blockquote><br class="">I have the very vaguest of memories that IIS can get a bit upset if you try to set a header which has some sort of sematic meaning (and in particular REMOTE_USER rings bells).  Are there any names like that?<br class=""></div></div></blockquote><div><br class=""></div><div> I do not have anything that mentioned REMOTE_USER. This configuration worked fine in SP 2 and since we moved to SP 3 this error starting happening. </div><br class=""><blockquote type="cite" class=""><div class=""><div class="">If you add a case to JIRA so I don't forget, it would not be hard to add better logging in the future.<br class=""><br class="">As for debugging it - I am assuming that this is a production machine?  If so then I have no ideas.<br class=""></div></div></blockquote><div><br class=""></div>Yes it is a production machine. I just wish that I could see what’s specifically throwing the error instead of just the xmltooling::IOException which the user gets. So let me get this right, the IDP posts back the SAML2 response , Shibboleth SP gets it, maps all the values which I can see in the shibd.log and it redirects them to my application URL passing the header data, so between passing the data through to IIS header and my page loading it errors with the xmltooling:IOException error.</div><div><br class=""></div><div>This is Shibboleth catching the error correct?</div><div><br class=""></div><div><br class=""></div><div><br class=""></div></body></html>