Shibboleth SP with Novell NAM IDP

Ian Young ian at iay.org.uk
Mon Sep 24 09:00:09 EDT 2012


On 24 Sep 2012, at 12:55, Peter Schober <peter.schober at univie.ac.at> wrote:

> There are a few strange things there, e.g. it does not list SAML2 in
> protocolSupportEnumeration (neither for the IDP nor AA or SP role) but
> only lists SAML2 protocol endpoints within these roles.

That will certainly cause problems.  In addition, I'd note that the protocolSupportEnumeration does include SAML 1 tokens but there are no endpoints with SAML 1 bindings.

A UK federation member ran a proof of concept of a later version of this software (now called NetIQ Access Manager, I believe) and the metadata we eventually ended up with for that entity just had protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol".

I have to admit that I don't know what the result of that proof of concept was; the entity in question has since been retired.  From what Leif is saying, though, you might have a tough row to hoe here, and if you have the option of running something else as your IdP it might be worth considering.

	-- Ian



-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20120924/1c8f6226/attachment.bin 


More information about the users mailing list