Symantec Access Management

wreply URL in WS-FED with SAML1.1

  • 1.  wreply URL in WS-FED with SAML1.1

    Posted Oct 19, 2018 07:52 PM

    Hi

     

    I am looking for some help in getting the wreply URL working for my WS-FED SAML1.1 based configuration.

     

    We are using the IDP initiated URL for WS-FED, with a wreply parameter in the request. The ACO property validfedtargetdomain has been populated, and the wreply URL gets validated against it. 

     

    However, when it comes to the point that WS-Response has been created and should be posted to wreply, it just ignores the parameter, and posts the response to AssertionConsumerDefaultURL configured in WSFED partnership, instead of wreply URL.

     

    My logs show the value of wreply parameter all through to this point. But then at this point 

     

    [SSO.java][processAssertionGeneration][resource is: /wtrealm=realmname&wa=wsignin1.0&wreply=value_of_wreply_url]

    [SSO.java][sendSecurityTokenResponse][securityTokenConsumerURL: the_default_ value_ Response_URL]

     

    Has anyone implemented wreply URL successfully? Any response will be appreciated. Thanks.