<div dir="ltr">Thanks Steven. Do you know how do I set opensaml.config.xml.unmarshall.strictMode to false? is that in idp.properties ?</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Sun, Oct 27, 2024 at 2:53 PM Steven Premeau <<a href="mailto:steven.premeau@maine.edu">steven.premeau@maine.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Ultimately you should reach out to the service provider to correct their request, as it the AuthnContextClassRef should be in a RequestedAuthnContext element <i>(and you can search the list archives for comments about requesting an unspecified nameid format)</i>:<div><br></div><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><font face="monospace"><samlp:AuthnRequest ID="_8dabfa33-8361-4634-9377-63bc62a78ea2"<br> Version="2.0"<br> IssueInstant="2024-10-27T17:34:21Z"<br> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br> AssertionConsumerServiceURL="<a href="https://x34.emaint.com/wc.dll?X3~SAML" target="_blank">https://x34.emaint.com/wc.dll?X3~SAML</a>"<br> Destination="<a href="https://idp.cua.edu/idp/profile/SAML2/POST/SSO" target="_blank">https://idp.cua.edu/idp/profile/SAML2/POST/SSO</a>"<br> ProviderName="<a href="http://emaint.com" target="_blank">emaint.com</a>"<br> xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<br> ><br> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://x34.emaint.com/SAML" target="_blank">https://x34.emaint.com/SAML</a></saml:Issuer><br> <samlp:NameIDPolicy <strike>Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"</strike><br> AllowCreate="true"<br> /></font><div><b style="font-family:monospace"> <samlp:RequestedAuthnContext></b></div></blockquote><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><div><font face="monospace"> <saml:AuthnContextClassRef</font></div></blockquote><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><div><font face="monospace"> xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"></font><span style="color:rgb(0,0,0);font-family:"Roboto Mono",Menlo,Monaco,"Courier New",monospace,Menlo,Monaco,"Courier New",monospace;font-size:12px">urn:</span><span style="color:rgb(0,0,0);font-family:"Roboto Mono",Menlo,Monaco,"Courier New",monospace,Menlo,Monaco,"Courier New",monospace;font-size:12px">oasis:names:tc:SAML:2.0:ac:</span><span style="color:rgb(0,0,0);font-family:"Roboto Mono",Menlo,Monaco,"Courier New",monospace,Menlo,Monaco,"Courier New",monospace;font-size:12px">classes:</span><span style="color:rgb(0,0,0);font-family:"Roboto Mono",Menlo,Monaco,"Courier New",monospace,Menlo,Monaco,"Courier New",monospace;font-size:12px">PasswordProtectedTransport</span></div></blockquote><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><div><font face="monospace"> </saml:AuthnContextClassRef></font></div></blockquote><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><div><font face="monospace"><b> </samlp:RequestedAuthnContext></b></font></div></blockquote><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><div><font face="monospace"></samlp:AuthnRequest></font></div><div><font face="monospace"><br></font></div><div><font face="monospace"><br></font></div></blockquote></blockquote><font face="arial, sans-serif">That said, the key change between version 4 and version 5 </font>
<span style="font-family:arial,sans-serif">likely</span> <font face="arial, sans-serif">causing your issue is documented in the release notes - <a href="http://goog_189559321" target="_blank">search for </a></font><a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500367/ReleaseNotes#:~:text=The%20XML%20processing,see%20Known%20Bugs)." target="_blank">opensaml.config.xml.unmarshall.strictMode</a>.<div><br></div><div>Steve.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Sun, Oct 27, 2024 at 1:58 PM Mohamed Lrhazi via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Hello,<div><br></div><div>An SP that is working with our version 4 IdP appears to fail with version 5. am getting the following error message:<br><div><br></div><div><h1 style="box-sizing:border-box;border:0px solid rgb(229,231,235);font-size:1rem;font-weight:500;margin:0px;line-height:1.5rem;word-break:break-word">Error unmarshalling message from input stream: Saw invalid child element {urn:oasis:names:tc:SAML:2.0:assertion}AuthnContextClassRef on parent {urn:oasis:names:tc:SAML:2.0:protocol}AuthnRequest</h1></div></div><div><br></div><div>Is there a workaround to accept these requests in version 5 ?</div><div><br></div><div>The requests look like this:</div><div><br></div><div><div style="color:rgb(0,0,0);font-family:"Roboto Mono",Menlo,Monaco,"Courier New",monospace,Menlo,Monaco,"Courier New",monospace;font-size:12px;line-height:18px;white-space:pre-wrap"><div><samlp:AuthnRequest <span style="color:rgb(0,0,255)">ID</span>=<span style="color:rgb(163,21,21)">"_8dabfa33-8361-4634-9377-63bc62a78ea2"</span></div><div> <span style="color:rgb(0,0,255)">Version</span>=<span style="color:rgb(163,21,21)">"2.0"</span></div><div> <span style="color:rgb(0,0,255)">IssueInstant</span>=<span style="color:rgb(163,21,21)">"2024-10-27T17:34:21Z"</span></div><div> <span style="color:rgb(0,0,255)">ProtocolBinding</span>=<span style="color:rgb(163,21,21)">"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</span></div><div> <span style="color:rgb(0,0,255)">AssertionConsumerServiceURL</span>=<span style="color:rgb(163,21,21)">"<a href="https://x34.emaint.com/wc.dll?X3~SAML" target="_blank">https://x34.emaint.com/wc.dll?X3~SAML</a>"</span></div><div> <span style="color:rgb(0,0,255)">Destination</span>=<span style="color:rgb(163,21,21)">"<a href="https://idp.cua.edu/idp/profile/SAML2/POST/SSO" target="_blank">https://idp.cua.edu/idp/profile/SAML2/POST/SSO</a>"</span></div><div> <span style="color:rgb(0,0,255)">ProviderName</span>=<span style="color:rgb(163,21,21)">"<a href="http://emaint.com" target="_blank">emaint.com</a>"</span></div><div> xmlns:<span style="color:rgb(0,0,255)">samlp</span>=<span style="color:rgb(163,21,21)">"urn:oasis:names:tc:SAML:2.0:protocol"</span></div><div> ></div><div> <saml:Issuer xmlns:<span style="color:rgb(0,0,255)">saml</span>=<span style="color:rgb(163,21,21)">"urn:oasis:names:tc:SAML:2.0:assertion"</span>><a href="https://x34.emaint.com/SAML" target="_blank">https://x34.emaint.com/SAML</a></saml:Issuer></div><div> <samlp:NameIDPolicy <span style="color:rgb(0,0,255)">Format</span>=<span style="color:rgb(163,21,21)">"urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"</span></div><div> <span style="color:rgb(0,0,255)">AllowCreate</span>=<span style="color:rgb(163,21,21)">"true"</span></div><div> /></div><div> <saml:AuthnContextClassRef xmlns:<span style="color:rgb(0,0,255)">saml</span>=<span style="color:rgb(163,21,21)">"urn:oasis:names:tc:SAML:2.0:assertion"</span>>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef></div><div></samlp:AuthnRequest></div><div><br></div></div></div><div>Thanks a lot,</div><div>Mohamed.</div></div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>
</blockquote></div>