Problem getting shibb 2.3.5 to work with workday

David Massie dhm24 at georgetown.edu
Tue Feb 7 16:12:35 GMT 2012


Has anyone gotten shibb 2.3.5 to work with workday?

Workday uses a form of SSO initiated login. Specifically:

1. User points browser to workday site: 
https://www.myworkday.com/usersdomain/login.flex
2. Workday redirects the user's browser to: 
https://local-shibb.mydomain.com/idp/profile/SAML2/Unsolicited/SSO
     During the redirect Workday drops several cookies
3. The user logs in via shibboleth and id sent back to workday.


I have set it up and am getting in a login redirect loop. For each 
redirect I see that another instance of the _idp_authn_ic_key cookie has 
been dropped.

I have checked my metadata -- in fact, I am using the same metadata that 
I use in the 2.1.5 instance we use in production that is able to log 
into workday.

I also checked my relying-party entry. The only difference between the 
2.1.5 and 2.3.5 versions is the profile ocnfiguration.

in 2.1.5 it is: ProfileConfiguration 
xsi:type="samlidpinit:UnsolicitedSAML2SSOProfile

in 2.3.5 it is: <rp:ProfileConfiguration xsi:type="saml:SAML2SSOProfile"

I checked the http headers and they appear to be posting to the correct 
ACS. And the assertion looks fine.

The only thing I can think of is something has changed in placing the 
cookies.

Does anyone have any advise???

-- 
Thanks,

Dave Massie
x73880



More information about the users mailing list