Highlighted
-Magnus- Super Contributor.
Super Contributor.
100 views

Redirect in metadata

Just realized that NAM tries to post into the redirect endpoint if metadata contains different endpoints for post/redirect .  i.e: 

md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://xx/idp/profile/SAML2/Redirect/SSO" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://xx/idp/profile/SAML2/POST/SSO" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"

Having different endpoints for post/redirect is a pretty common scenario when working with shibboleth. 

Removing the HTTP-Redirect element from metadata makes it work, but it is a lot of work when using a metadata feed. 

regards,

magnus 

0 Likes
2 Replies
Micro Focus Frequent Contributor
Micro Focus Frequent Contributor

Re: Redirect in metadata

Is NAM a Service Provider in this case ? How are you initiating the request. Please attached SAML trace if possible.

0 Likes
-Magnus- Super Contributor.
Super Contributor.

Re: Redirect in metadata

Hi 

Nam is SP in this case. I'm sorry for not providing a trace..  but the problem is submitted as bug:1139552

It can be reproduced by importing metadata feed from i.e.  http://eid.svelegtest.se/metadata/mdx/role/idp.xml and use one of the IDP that has two SingleSignOnService elements and where the redirect binding element is before the post element in metadata...

NAM is then trying to post into the redirect endpoint, which returns a http 400 error. (redirect should be http GET) When removing the redirect element from metadata or place the post before redirect it works as expected.

best regards Magnus 

 

 

 

 

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.