Problem getting shibb 2.3.5 to work with workday
David Massie
dhm24 at georgetown.edu
Tue Feb 7 16:12:35 GMT 2012
Has anyone gotten shibb 2.3.5 to work with workday?
Workday uses a form of SSO initiated login. Specifically:
1. User points browser to workday site:
https://www.myworkday.com/usersdomain/login.flex
2. Workday redirects the user's browser to:
https://local-shibb.mydomain.com/idp/profile/SAML2/Unsolicited/SSO
During the redirect Workday drops several cookies
3. The user logs in via shibboleth and id sent back to workday.
I have set it up and am getting in a login redirect loop. For each
redirect I see that another instance of the _idp_authn_ic_key cookie has
been dropped.
I have checked my metadata -- in fact, I am using the same metadata that
I use in the 2.1.5 instance we use in production that is able to log
into workday.
I also checked my relying-party entry. The only difference between the
2.1.5 and 2.3.5 versions is the profile ocnfiguration.
in 2.1.5 it is: ProfileConfiguration
xsi:type="samlidpinit:UnsolicitedSAML2SSOProfile
in 2.3.5 it is: <rp:ProfileConfiguration xsi:type="saml:SAML2SSOProfile"
I checked the http headers and they appear to be posting to the correct
ACS. And the assertion looks fine.
The only thing I can think of is something has changed in placing the
cookies.
Does anyone have any advise???
--
Thanks,
Dave Massie
x73880
More information about the users
mailing list