Interoperation with pingone
James Miller
jmiller at turnitin.com
Wed Sep 25 04:59:14 EDT 2013
Hi all,
I see an entry in the shibboleth2 wiki which states the following about
configuring a shibboleth sp to work with pingone's IDP.
When configuring Shibboleth SP to use a PingFederated (PingIdentity) IdP,
> do not use the "/idp/startSSO.ping" endpoint as this is a proprietary Ping
> endpoint for IdP-Initiated SSO which is not for SAML 2 requests and will
> drop the RelayState parameter. Use the "/idp/SSO.saml2" endpoint for
> expected Shibboleth SP behavior
>
But I have no idea where to actually set that endpoint.
For other route-to specific-idp scenarios, I have stuff like this in my
session initiator:
<Path name="someidp" entityID="urn:mace:incommon:idps.entityid" />
In my metadata section, the entity id for the idp gets defined and
everything works.
With pingone if I try that, their IDP throws an error
> REQ_002a[f3c6319c]
>
> The system is unable to determine which IdP to use for your SSO request.
> Please add idpid parameter to your SSO request (e.g.
> https://sso.connect.pingidentity.com/sso/idp/SSO.saml2?idpid=<idpid>),
> perform an IdP-initiated SSO or PingOne-initiated SSO first.
>
I (perhaps mistakenly) assume this is related to the ping post on the
shibboleth wiki, but I have no idea where to override the endpoint.
Could someone who has successfully integrated their SP with PingOne, I
would appreciate any pointers you can provide.
Thanks,
James
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130925/7f7feddf/attachment.html
More information about the users
mailing list