IdP for Blackboard Connect

Chad La Joie lajoie at itumi.biz
Sun Sep 2 18:43:56 EDT 2012


On Sun, Sep 2, 2012 at 6:09 PM, Michael Ghens <mghens at sbcc.edu> wrote:
> No, Blackboard is the SP

Right, so they aren't implementing IdP-initiated SSO, which, as its
name suggests, is all about the IdP.

> We are having problems connecting with BlackBoard Transact. From what I
> can tell Our IDP is actually authenticating and the attributes are
> actually being sent over.
>
> What is strange about the situation is that my IDP sucks down their
> metadata.  However, on their side, the only thing that blackboard
> requires is
>
> Single Single Sign On Url
> and
> Attribute Service Url
>
> My IDP's metadata has not been exchanged with BB.

Most custom built and commercial SAML implementations don't support
metadata which makes managing them at scale a right pain in the ass.
That BB falls in to this category, given what else has been said about
them, doesn't surprise me too much.

> Just wondering if there was anything that I could do in the
> relying-party.xml?

You'll need to find out what exactly is wrong.  Just a shot in the
dark guess: the IdP is responding with SAML v2, encrypting the
assertion, and BB's SP doesn't support encrypted content.  *IF* that
is true, then you can create a custom relying party configuration for
them that adjusts what, if anything, gets signed/encrypted.

-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list