open ports / version mismatch
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 12 14:30:27 EDT 2013
> He sent me his handlers.xml; your guess seems to be correct, as far as I can
> read this https://gist.github.com/tingletech/5767470
Yes, it's broken given what you described in its log, and Peter is probably correct about why, it's a missing default on a RelyingParty override most likely.
> I'm not sure I'm going to have any luck convincing him anything is wrong with
> this configuration since it works with other SPs he has tested with.
If he repeats the same override he defined for yours for some other SP, I bet it breaks in the same way.
> He can not provide me with any configuration information for these SPs that work
> with this IdP; and Scott suggested I should not change my SP to
> accommodate this IdP configuration.
Well, if you really want to, go for it, but setting authnContextClassRef to the Password constant means you'll break any IdP that for whatever reason might be offering something else. It's just not a setting you use unless you need it.
> Testing the SP with this IdP seems to be on some checklist as a pre-reqresite
> to them registering my SP metadata with InCommon. Do you think testing
> with testshib.org is a good enough test?
The best resources are probably what InCommon defines in the technical material about how to configure things, how to make sure SAML 2 support is done properly, etc.
-- Scott
More information about the users
mailing list