Help configuring custom relying party for a relaystate url

Cantor, Scott cantor.2 at osu.edu
Tue Aug 20 11:28:04 EDT 2013


On 8/20/13 11:24 AM, "Karla Borecky" <kborecky at smith.edu> wrote:

>I am working with a vendor who has just given me these two urls: one is
>the "service" url, the other is the "consume" url - and said that
>previously, that's all they gave people and it would work. No metadata,
>so I believe I am correct in thinking I need
> to create a custom relying party section for them.

No. You need metadata for them, which you should supply in a file with
metadata for all such unmanaged partners, and then just load it. You don't
need other special rules.

>But using the SAML2SSOProfile doesn't seem to work. When I go to their
>test site, it just brings up our IdP's metadata. I assume that's because
>it doesn't know what to do with the rest of the URL, maybe? The resulting
>url looks like this:

That's not a valid endpoint at the IdP. That you'll have to take up with
them, it's not up to your IdP how the requests are generated.

>I've tried to figure out how to configure the relying party to work with
>a relaystate url, if that is what I should be doing, but the only
>references I could find had an RPID in their relaystate string - which
>they don't have.

None of that is relevant to the issue.

-- Scott




More information about the users mailing list