Help configuring custom relying party for a relaystate url

Cantor, Scott cantor.2 at osu.edu
Tue Aug 20 12:32:18 EDT 2013


On 8/20/13 12:18 PM, "Karla Borecky" <kborecky at smith.edu> wrote:

>Well, I did ask them to give me metadata, and they didn't really know how
>to generate it.

That isn't all that uncommon, but the IdP requires it, so that means you
have to mock it up based on the piecemeal information you get. It's
inevitable to run into this case at some point.

> I had to give them examples of what it should have. After it looked sort
>of OK, I configured everything for them the way I usually do - and used
>the aacli
> shell script to make sure it was giving them attributes etc. - but still
>it just displayed the IdP metadata when you went to the site.

They have to send their requests to the right endpoint. If they don't use
metadata, which I'm sure is the case, then you have to tell them all of
that manually. Essentially the inverse of the above. The endpoint depends
on the binding. Redirects would need to go to
/idp/profile/SAML2/Redirect/SSO

-- Scott




More information about the users mailing list