<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
HI,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
yes I noticed the wrong URLs</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
ended up with</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<SessionInitiator target="/bin/idm/open/register01.pl?en" Location="/Login_en"</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
and</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<SessionInitiator target="/bin/idm/open/register01.pl?fi" Location="/Login_fi"</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
thanks for the help.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div style="font-size:12pt;color:#000000;background-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif" dir="ltr" id="divtagdefaultwrapper">
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
Terveisin/Regards</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
<b> </b></div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
<b>Scott Alexander</b></div>
<div style="margin: 0px;"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: black;">Asiantuntija, järjestelmät
</span><span style="font-family: Calibri, sans-serif; font-size: 9pt; color: black;"></span><span style="font-family: "Calibri", sans-serif; font-size: 11pt; color: rgb(31, 73, 125);">Systems Specialist</span></div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
 </div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
Humak</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
Humanistinen ammattikorkeakoulu</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
University of Applied Sciences</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
<a href="http://www.humak.fi/" target="_blank">www.humak.fi</a></div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
 </div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
Tel. +358 (0)50 411 9556<br>
<br>
</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
<a href="mailto:scott.alexander@humak.fi" target="_blank">scott.alexander@humak.fi</a></div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> 21 May 2024 15:04<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Peter Schober <peter.schober@univie.ac.at><br>
<b>Subject:</b> [HUOMIO! VIESTI TOD. NÄK. HUIJAUS] Re: Why correct SessionInitiator isn't called</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">Scott Alexander via users <users@shibboleth.net> [2024-05-21 08:41 CEST]:<br>
> The location is different for each SessionInitiator<br>
> but even though I use location in the browser<br>
> (/bin/idm/open/register01_fi.pl) for the fi extension it always uses<br>
> the first.<br>
<br>
> <SessionInitiator Location="/bin/idm/open/register01.pl" type="SAML2" entityID="<a href="https://testi.apro.tunnistus.fi/idp1">https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftesti.apro.tunnistus.fi%2Fidp1&data=05%7C02%7C%7C8e6acc4db38b4372d69608dc798e3cda%7Ca30a558eb6084b2c8f39a7fa426fa49d%7C0%7C0%7C638518899040784375%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=hnC%2FpytAO88%2F6YAKkWjTmhjM5hUUsrQ7d%2FGIKOTjKfg%3D&reserved=0</a>"><br>
[...]<br>
> <SessionInitiator Location="/bin/idm/open/register01_fi.pl" type="SAML2" entityID="<a href="https://testi.apro.tunnistus.fi/idp1">https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftesti.apro.tunnistus.fi%2Fidp1&data=05%7C02%7C%7C8e6acc4db38b4372d69608dc798e3cda%7Ca30a558eb6084b2c8f39a7fa426fa49d%7C0%7C0%7C638518899040797134%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=d8ZZf46JTsBTf51T1Gk%2F8CmfqiW0rtYb4BPvpfDavZc%3D&reserved=0</a>"><br>
<br>
Are you sure the Shibboleth SP is even involved here and not something<br>
else?<br>
I'm asking because the 'Location' XML attribute is documented to be<br>
relative to the handlerURL (defaulting to '/Shibboleth.sso')<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065334685/SessionInitiator">https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FSP3%2Fpages%2F2065334685%2FSessionInitiator&data=05%7C02%7C%7C8e6acc4db38b4372d69608dc798e3cda%7Ca30a558eb6084b2c8f39a7fa426fa49d%7C0%7C0%7C638518899040805551%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=5UfKSUW0ig5%2BH0z2a%2BIOEDo3NYpR9OGyEpjpoLMho%2F4%3D&reserved=0</a><br>
and so the above would only do anything if accessed at<br>
  /Shibboleth.sso/bin/idm/open/register01.pl<br>
While at<br>
  /bin/idm/open/register01.pl<br>
you'd not be talking to the Shibboleth SP itself at all.<br>
<br>
(Also note that if you're going to create custom endpoints below<br>
/Shibboleth.sso/ anyway you might as well keep them simpler than<br>
'/bin/idm/open/register01.pl' which has the potential of confusing<br>
yourself that the Shib SP somehow runs your Perl script or whatever.)<br>
<br>
Also note that unless you need the authn request to be signed it might<br>
be easier to have your own code create the complete authentication<br>
request, with extensions and all, from your own code. At least it<br>
looks to me like you're able to run your own code on that server<br>
anyway (.pl suggesting a Perl script to me).<br>
That may be easier and more flexible than trying to make the SP do it<br>
for you.<br>
<br>
HTH,<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7C%7C8e6acc4db38b4372d69608dc798e3cda%7Ca30a558eb6084b2c8f39a7fa426fa49d%7C0%7C0%7C638518899040811639%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=Klad6%2FXBAkpv1nWAHMPcK9J21MYF9ul9WoCGiI6uDkg%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>