RemedyForce/SalesForce Idp Configuration

Ben Branch BBranch at uco.edu
Mon Aug 4 11:31:40 EDT 2014


Just for my own curiosity, what are you populating the EPPN with?  Is this an email address, a banner id? Or is this some other custom value that you are using to populate this attribute?

Ben Branch
UNIX/Linux Administrator
University of Central Oklahoma
ITIL Foundation v3, Network+, RHCSA

100 N. University Drive, Box 122
Edmond, OK 73034
D: 405.974.2649 | M: 405.550.6804 | bbranch at uco.edu | www.uco.edu

"I am wiser than this man, for neither of us appears to know anything great and good; but he fancies he knows something, although he knows nothing; whereas I, as I do not know anything, so I do not fancy I do. In this trifling particular, then, I appear to be wiser than he, because I do not fancy I know what I do not know."  - Socrates

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Tuesday, July 29, 2014 10:43 AM
To: Shib Users
Subject: Re: RemedyForce/SalesForce Idp Configuration

On 7/26/14, 1:04 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>I would have the same questions, but unfortunately there's nobody who
>can answer them except for the vendor, or I guess somebody who's
>managed to make it work. I'm being asked to set this up soon, but I
>haven't done it yet.

I got access to our sandbox just this morning and started working on configuring this.

So far, I'm seeing no requirement to send them a NameID, as I think another poster mentioned. You can provide an Attribute name and format to look for, and I gave it the EPPN OID and URI name format, and that appears to work.

There are a lot of open questions I'll have to dig into about provisioning, and there's the usual questions like how do we actually trigger SSO for users (all I'm seeing so far is password prompts). I got it to accept an encrypted assertion from the IdP without any non-default options in my IdP, but so far it's not actually logging me in yet.

Overall, about as easy/hard as any other vendor's non-Shibboleth SAML implementation.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
**Bronze+Blue=Green** The University of Central Oklahoma is Bronze, Blue, and Green! Please print this e-mail only if absolutely necessary!

**CONFIDENTIALITY** -This e-mail (including any attachments) may contain confidential, proprietary and privileged information. Any unauthorized disclosure or use of this information is prohibited.


More information about the users mailing list