Shibboleth IdP integration with Oracle 11g Identity Federation

Peter Schober peter.schober at univie.ac.at
Wed Mar 27 06:23:04 EDT 2013


* lalithj <j_lalith at hotmail.com> [2013-03-27 10:16]:
> Now the name format error is no more happening because the OIF
> configuration changed to transient format,

3 hours earlier you still said:

* lalithj <j_lalith at hotmail.com> [2013-03-27 07:19]:
> Please advice if anything is not correct,
[...]
> Authentication Request NameID Format : Email Address

Which is why I pointed it out.

> Even though it is other software (Oracle Identify Federation), it is
> having the URLs pointing to our IdP, so that is why I listed those
> end points in my previous post for a verfification,

You can find all URLs for your protocol endpoints in your
idp-metadata.xml
Now which protocol endpoint is "correct" for the other software I
cannot know, as this depends on the supported protocol bindings.
If HTTP-Redirect is supported then yes, the URL you posted seems OK.
Same for the SOAP protocol binding (as there might also be Artifact
resolution happending over SOAP). No idea what /kind/ of URL the other
software expects, so it's impossible to say whether your URLs are
correct.
You have all the information available in your own metadata. You'll
need to ask the other software's vendor about what it wants, needs,
supports, etc. and configure it appropriately.

> However still SP is getting the above bad certificate error,

To which Kevin already replied:

* Kevin P. Foote <kpfoote at iup.edu> [2013-03-26 13:37]:
> > I am under the impression there is also an certificate issue in SP
> > side probably loading our IdP certificate which is a self signed
> > certificate.
> 
> This is all via the lame GUI so yea you have to match your
> self-signed cert with the proper endityId and such within OIF.

So I'd try what was suggested before re-posting the same questions.
-peter


More information about the users mailing list