<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Hi Chris, </div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof"><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">I've seen this before... and the missing "destination" element in Okta is a pretty well-known
 issue when you google it: <a href="https://support.okta.com/help/s/question/0D51Y00008vdbOKSAY/destination-attribute-not-set-in-samlresponse?language=en_US" id="LPlnk651701" class="OWAAutoLink" data-loopstyle="linkonly">
https://support.okta.com/help/s/question/0D51Y00008vdbOKSAY/destination-attribute-not-set-in-samlresponse?language=en_US</a></span></div>
<div class="elementToProof"><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><br>
</span></div>
<div class="elementToProof"><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">And I think this comes about from using the "SAML Service Provider" template when building
 the integration with the IDP in Okta, which neglects to properly set Destination and IIRC doesn't give you the full set of "Advanced" options by default.
</span><span style="letter-spacing: normal; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 14.6667px; font-weight: 400; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">Instead, there's another
 generic "Create New App - Web - SAML 2.0" or something like that in the Okta admin</span><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">, which lets you specify
 the Recipient and Destination manually (see: <a href="https://help.okta.com/en-us/content/topics/apps/aiw-saml-reference.htm" id="LPlnk288231">
https://help.okta.com/en-us/content/topics/apps/aiw-saml-reference.htm</a>)</span></div>
<div class="elementToProof"><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><br>
</span></div>
<div class="elementToProof"><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">There may have been deprecations / updates to how they do things though, and I haven't
 looked at the Okta Admin UI since I left the consulting business. I ran into this exact problem with a number of Okta proxy configs. </span></div>
<div class="elementToProof"><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><br>
</span></div>
<div class="elementToProof"><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">Feel free to ping me in the Internet2 slack if you'd like to get another set of eyes
 on it sometime.</span></div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<p style="margin-bottom: 7.5pt;"><span style="font-family: "Arial Narrow", sans-serif; font-size: 11.5pt; color: rgb(0, 47, 108);"><b>Kellen Murphy</b></span><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><br>
</span><span style="font-family: "Arial Narrow", sans-serif; font-size: 10.5pt; color: rgb(0, 47, 108);"><i>he/him/his<br>
Identity Architecture & Solutions Engineer</i></span></p>
<p style="line-height: 11.25pt; margin-bottom: 7.5pt;"><span style="font-family: "Arial Narrow", sans-serif; font-size: 10.5pt; color: rgb(0, 47, 108);"><b>E
</b></span><span style="font-family: "Arial Narrow", sans-serif; font-size: 10.5pt; color: blue;"><a href="mailto:wfx6yz@virginia.edu" target="_blank" id="OWAc06d85d5-a779-5b1e-76e0-aa04afbf1c1d" class="OWAAutoLink" data-loopstyle="linkonly" style="margin-top: 0px; margin-bottom: 0px; color: blue;">wfx6yz@virginia.edu</a></span><span style="font-family: "Arial Narrow", sans-serif; font-size: 10.5pt; color: rgb(0, 47, 108);"><br>
<b>T </b>+1 (434) 243-7248</span></p>
<p style="margin-bottom: 7.5pt;"><span style="font-family: "Arial Narrow", sans-serif; font-size: 11.5pt; color: rgb(0, 47, 108);"><b>University of Virginia</b></span><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><br>
</span><span style="font-family: "Arial Narrow", sans-serif; font-size: 10.5pt; color: rgb(0, 47, 108);">Information Technology Services (ITS)<br>
Michie South<br>
914 Emmet Street N.<br>
P.O. Box 400217<br>
Charlottesville, VA 22903</span></p>
<p style="line-height: 11.25pt; margin-bottom: 7.5pt;"><span style="font-family: "Arial Narrow", sans-serif; font-size: 10.5pt; color: rgb(235, 95, 12);"><b><a href="https://its.virginia.edu/" target="_blank" id="OWA40f0b1a2-51f8-3ae0-875a-9a0600b156ff" class="OWAAutoLink" data-loopstyle="linkonly" style="margin-top: 0px; margin-bottom: 0px; color: rgb(235, 95, 12);">its.virginia.edu</a></b></span></p>
<p><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(235, 95, 12);"><a href="https://brand.virginia.edu/" target="_blank" id="OWAdddad167-4205-d7ad-8e55-f7b4aeb395d0" class="OWAAutoLink" data-loopstyle="linkonly" style="margin-top: 0px; margin-bottom: 0px; color: rgb(235, 95, 12);"><img alt="University of Virginia" style="width: 1.77in; height: 0.447in; margin-top: 0px; margin-bottom: 0px;" data-outlook-trace="F:1|T:1" src="cid:27085585-5976-490a-b6c7-e41fbb13216a"></a></span></p>
<p><span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><a href="https://www.linkedin.com/company/uva-information-technology-services/" id="OWA8853aa23-3999-c4fb-dd5d-9c0b37ec387a" class="OWAAutoLink" title="https://www.linkedin.com/company/uva-information-technology-services/" data-loopstyle="linkonly" style="margin-top: 0px; margin-bottom: 0px;"><img id="imageSelected0" width="23" height="23" style="width: 23px; height: 23px; margin-top: 0px; margin-bottom: 0px;" data-outlook-trace="F:1|T:1" src="cid:3459c01c-0f9e-4a10-afcc-0f9122419783"></a></span></p>
</div>
<div id="appendonsend"></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div id="divRplyFwdMsg" dir="ltr"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Christopher Bongaarts via users <users@shibboleth.net><br>
<b>Sent:</b> Friday, December 8, 2023 1:42 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Christopher Bongaarts <cab@umn.edu><br>
<b>Subject:</b> Okta missing Destination in SAML response</span>
<div> </div>
</div>
<div><span style="font-size: 11pt;">Surely others have configured a Shibboleth IdP to use SAML proxy<br>
authentication with Okta as their IdP?<br>
<br>
We are trying to set this up (Shib IdP 4.1.7) but are getting an error<br>
with the SAML response from Okta:<br>
<br>
2023-12-08 12:14:58,655 - 128.101.xx.yy - ERROR<br>
[org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:170]<br>
- Message Handler:  SAML message intended destination endpoint URI<br>
required by binding was empty<br>
2023-12-08 12:14:58,656 - 128.101.xx.yy - WARN<br>
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:197] -<br>
Profile Action WebFlowMessageHandlerAdaptor: Exception handling message<br>
org.opensaml.messaging.handler.MessageHandlerException: SAML message<br>
intended destination (required by binding) was not present<br>
     at<br>
org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler.checkEndpointURI(ReceivedEndpointSecurityHandler.java:172)<br>
<br>
We were able to confirm that there is no Destination attribute on the<br>
SAML response.  This seems like a bug in Okta's implementation, but not<br>
sure how anyone else would have been able to get it working.  Anyone<br>
else tried this?  Did we miss a step somewhere?<br>
<br>
Thanks,<br>
<br>
--<br>
%%  Christopher A. Bongaarts   %%  cab@umn.edu          %%<br>
%%  OIT - Identity Management  %%  <a href="http://umn.edu/~cab" id="OWAe0f525c0-8e28-923a-4c32-075735259991" class="OWAAutoLink" data-auth="NotApplicable" data-loopstyle="linkonly">
http://umn.edu/~cab</a>  %%<br>
%%  University of Minnesota    %%  +1 (612) 625-1809    %%<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" id="OWAc534d90a-cf32-0e79-f980-d61679192aea" class="OWAAutoLink" data-auth="NotApplicable" data-loopstyle="linkonly">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</span></div>
</body>
</html>