Question regarding configuration of shibboleth using NativeSPBackDoor

Cantor, Scott cantor.2 at osu.edu
Wed Jun 27 21:16:57 BST 2012


On 6/27/12 4:08 PM, "Chu, Man Sin" <ManSin.Chu at alliancebernstein.com>
wrote:

>  I have a vendor that will execute an IdP-initiated browser POSTed
>assertion
> to me (Service Provider).

That is not what this feature is for.

>  I need to process this SAML assertion and route it to an internal site.

Why? For what purpose? The assertion is meant to be processed by an SP
implementation, not by your internal site.

>  They gave me a metadata file containing x.509 certificate.  From what I
>read on the shibboleth document, It indicating that I should use
>NativeSPBackDoor.

No, you shouldn't. That isn't even released yet, it's a beta release
feature. It isn't anything to do with normal SAML usage, it's for
integrating non-SAML mechanisms into the system.

The metadata file they gave you is how you provision the SP with what it
needs to communicate with that IdP. The wiki explains how to install the
software and how to configure it to communicate that an IdP.


> 
> I am running iis6.0.  I am not sure how to configure this.

IIS installation and use is documented, so unless you want to explain what
it is you don't understand in the existing documentation, there's not much
else I can do.

-- Scott



More information about the users mailing list