Does Shibboleth SP have any per-IDP config?
David Langenberg
davel at uchicago.edu
Thu Feb 6 17:31:37 EST 2014
The answers are yes and no. You could, with application overrides, make
your SP behave differently for each IdP you integrate with. However, I'm
betting the problems here are at the IdP end especially if you're
integrating via InCommon. Unfortunately, you're going to have to slog it
out with the IdP admins in this case. Turning your logs up & capturing the
decrypted assertions will assist with identifying where the problems lie
and assist with tweaks you may want to make to your attribute-map to
accommodate the other IdP's "specialness". As for InCommon not releasing
attributes, that's a new one. Perhaps the IdP admin is expecting your SP
to be tagged by InC as an R&S SP which would trigger a filter policy
automatically & that's what they mean?
Dave
On Thu, Feb 6, 2014 at 3:14 PM, Ken Weiss <ken.weiss at ucop.edu> wrote:
> I'm pretty sure the answer is 'no', but I wanted to ask the broader group
> just to be certain.
>
> If my Shibboleth SP works with 3 different IDPs, but doesn't work with 3
> others (failing in a different way for each of them), it's a pretty safe
> bet that the configuration issues are with the IDP, not my SP, right?
>
> I have one IDP that is returning two identical email addresses in the
> 'mail' attribute. That's causing our application to error out, which we
> need to fix since email is a multi-valued attribute. But it's got nothing
> to do with my SP.
>
> I have one that isn't authorizing to my application correctly, which is
> almost certainly a result of the IDP not releasing the right attributes.
>
> And I have one that, for reasons that truly baffle me, reports that
> "InCommon is not releasing the proper attributes." I have no idea what
> InCommon would have to do with this - all they do is deliver the metadata
> for my SP. Other than that, InCommon is not involved in the interaction,
> since I'm no longer using InCommon's Discovery Service.
>
> Anyway, before I tell them all to look at their own IDP configuration, I
> thought it would be good to get a quick sanity check from some people that
> have actually run an IDP at some point in their life (unlike me...).
> Thanks!
>
> --Ken
> ------------------------------------------------------------
> Ken Weiss ken.weiss at ucop.edu
> UC Office of the President 510-587-6311 (office)
> California Digital Library 916-905-6933 (mobile)
> UC Curation Center
> 415 20th Street, 4th Floor
> Oakland, CA 94612
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140206/16704289/attachment-0001.html
More information about the users
mailing list