<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RelayState error using AD FS 3 for Enterprise Login in ArcGIS Online Questions</title>
    <link>https://community.esri.com/t5/arcgis-online-questions/relaystate-error-using-ad-fs-3-for-enterprise/m-p/248719#M12206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;We recently encountered an error where iOS devices were failing to log into a newly set up AD FS endpoint with a rather cryptic error: "The required parameter RelayState was missing or invalid".&amp;nbsp; The error was appearing in the AD FS event logs on the window server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears that this error is usually caused by the SAML cookies exceeding the 4kb cookie limit , which results in a truncated cookie being sent to the endpoint, which is certainly invalid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://social.msdn.microsoft.com/Forums/vstudio/en-US/af0ac0c0-fdc8-42aa-91f5-945a29eec333/adfs-20-web-sso-not-working-in-current-versions-of-safari-for-windows-or-ios" title="https://social.msdn.microsoft.com/Forums/vstudio/en-US/af0ac0c0-fdc8-42aa-91f5-945a29eec333/adfs-20-web-sso-not-working-in-current-versions-of-safari-for-windows-or-ios"&gt;ADFS 2.0 Web SSO not working in current versions of Safari for Windows or iOS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It turned out that the workaround to the problem was to &lt;STRONG&gt;uncheck &lt;/STRONG&gt;the settings under Enterprise Login advanced settings&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Encrypt Assertion&lt;/LI&gt;&lt;LI&gt;Enable Signed Request&lt;/LI&gt;&lt;LI&gt;Propagate logout to Identity Provider&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #444444; font-family: Verdana, Helvetica, sans-serif; font-size: 12px;"&gt;For some reason, enabling all of these options resulted in cookies that were too large and caused the failures.&amp;nbsp; Hopefully this information can help others who run into the same issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Mar 2016 20:53:39 GMT</pubDate>
    <dc:creator>LucasScharenbroich</dc:creator>
    <dc:date>2016-03-29T20:53:39Z</dc:date>
    <item>
      <title>RelayState error using AD FS 3 for Enterprise Login</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/relaystate-error-using-ad-fs-3-for-enterprise/m-p/248719#M12206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;We recently encountered an error where iOS devices were failing to log into a newly set up AD FS endpoint with a rather cryptic error: "The required parameter RelayState was missing or invalid".&amp;nbsp; The error was appearing in the AD FS event logs on the window server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears that this error is usually caused by the SAML cookies exceeding the 4kb cookie limit , which results in a truncated cookie being sent to the endpoint, which is certainly invalid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://social.msdn.microsoft.com/Forums/vstudio/en-US/af0ac0c0-fdc8-42aa-91f5-945a29eec333/adfs-20-web-sso-not-working-in-current-versions-of-safari-for-windows-or-ios" title="https://social.msdn.microsoft.com/Forums/vstudio/en-US/af0ac0c0-fdc8-42aa-91f5-945a29eec333/adfs-20-web-sso-not-working-in-current-versions-of-safari-for-windows-or-ios"&gt;ADFS 2.0 Web SSO not working in current versions of Safari for Windows or iOS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It turned out that the workaround to the problem was to &lt;STRONG&gt;uncheck &lt;/STRONG&gt;the settings under Enterprise Login advanced settings&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Encrypt Assertion&lt;/LI&gt;&lt;LI&gt;Enable Signed Request&lt;/LI&gt;&lt;LI&gt;Propagate logout to Identity Provider&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #444444; font-family: Verdana, Helvetica, sans-serif; font-size: 12px;"&gt;For some reason, enabling all of these options resulted in cookies that were too large and caused the failures.&amp;nbsp; Hopefully this information can help others who run into the same issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2016 20:53:39 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/relaystate-error-using-ad-fs-3-for-enterprise/m-p/248719#M12206</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2016-03-29T20:53:39Z</dc:date>
    </item>
  </channel>
</rss>

