Shibboleth IdP integration with Oracle 11g Identity Federation
Kevin P. Foote
kpfoote at iup.edu
Wed Mar 27 09:21:07 EDT 2013
On Wed, 27 Mar 2013, lalithj wrote:
> In that case do you think worth trying out below
>
> https://ouridp.vu.edu.au:8443/idp/profile/SAML2/SOAP/ArtifactResolution
Your soap stuff is really unnecessary.. I never dealt with Artifact at
all.
..Couple things to note..
This is all on the OIF "Service Provider" config pages..
First OIF takes the subject of the assertion the NameID you are sending and looks
this up in a directory store somewhere. This is controlled on the
Identity and Access folder >> YourOIF >> SAML 2.0 tab. This is where you
can map / not map your identities that are coming from your IdP.
You could be having issues with the signing/not-signing of assertions from your IdP..
Controlled at OIF: Identity and Access folder >> YourOIF >> Common tab -
Require Signed Assertions checkbox .. ALSO under the SAML 2.0 tab -
Required Signed Assertions checkbox.
You can selectively sign/not sign from your ShibIdP .. I believe that is
what I did.. checking my back notes now. Also I'm encoding a specific
NameID that I want to send to OIF as the match on the backend.
Needless to say all of this, once you config on your OIF needs to match
the metadata and RP entry that your IdP has.
I'll keep looking back through my notes..
Writing something up on local wiki now, then will move to shib-wiki once its
semi sensible.. :P
------
thanks
kevin.foote
More information about the users
mailing list