Shibboleth IdP integration with Oracle 11g Identity Federation

Cantor, Scott cantor.2 at osu.edu
Mon Mar 25 21:46:37 EDT 2013


On 3/25/13 9:31 PM, "lalithj" <j_lalith at hotmail.com> wrote:

>Fully understand, from IdP point of view even I got no idea what they are
>doing,

I know exactly what they're doing (as regards NameIDPolicy), whether they
do or not, as I explained in my response. They claim to require a NameID
with a Format of email address. If they do require that, then that's an
appropriate thing to do. If not, it's not.

>Also I can't understand even below  request, does not look like SAML to
>me,
>is this SAML 1.0 ?
><ns12:AuthnRequest xmlns:wsa ......

No, that's SAML 2.0. If you need some basic XML material on namespaces,
prefixes, etc., w3schools.com is a pretty good resource.

>It is possible that they have configured OIF incorrectly for this
>integration,

Whether it's correct or not in that respect depends on what their
requirements are.

>Considering their exercise is based on a standard Oracle OIF platform, is
>there any reference or document explalning how OIF (as a SP) should be
>integrated with Shibboleth IdP,

Not that I'm aware. One configures based on one's technical requirements,
which requires understanding SAML and being able to translate those
requirements into the product's terminology. There are best practices and
things that are good or less good, but ultimately as long as they follow
the standard, we try to support it. Whether you're prepared to change your
IdP's behavior to do what they want is a different question.

>Or do you know any potention issues of OIF with Shibboleth IdP,

Since nobody who has done anything with OIF has recorded any findings in
the wiki under CommercialInterop, there's nothing there that I know of. I
created a page for it years ago.

-- Scott




More information about the users mailing list