Help configuring custom relying party for a relaystate url

Karla Borecky kborecky at smith.edu
Tue Aug 20 12:43:50 EDT 2013


When it didn't work at first, I assumed it was because they didn't have any
assertion consumers in their metadata. Then they put some in, but they are
pointing every one to the same thing:


<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
https://testing3.hiretouch.com/admin/saml/consume/" index="1"/>

<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
Location="https://testing3.hiretouch.com/admin/saml/consume/" index="2"/>

<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="
https://testing3.hiretouch.com/admin/saml/consume/" index="3"/>

<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="
https://testing3.hiretouch.com/admin/saml/consume/" index="4"/>

Maybe this is some sort of super bit of code that is the all-weather tire
of assertion consumers, but...


On Tue, Aug 20, 2013 at 12:30 PM, Ian Rifkin <irifkin at brandeis.edu> wrote:

> Hi Scott,
>
>
> No. You need metadata for them, which you should supply in a file with
>> metadata for all such unmanaged partners, and then just load it.
>
>
> Can you explain this more? Do you mean Karla should insist the vendor
> supply metadata or are you talking about *creating* metadata; If the
> latter, is there any information on how to do that / what should that look
> like?
>
>
>> That's not a valid endpoint at the IdP. That you'll have to take up with
>> them, it's not up to your IdP how the requests are generated.
>>
>
> They could be going to the wrong IdP URL for the protocol (especially if
> they're not getting it from your metadata), right?
>
> Regards,
> Ian
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130820/d2046922/attachment.html 


More information about the users mailing list