Revised Revised DocuSign Identity Priorities
David Bantz
dabantz at alaska.edu
Wed Jul 30 20:56:22 EDT 2014
After many months of stumbling attempting to use our Shibboleth IdP for authentication to DocuSign, we’re seeing systematic failure to process the SAML assertion from our IdP ("The SAMLResponse structure did not contain expected nodes or was incorrectly formatted - No assertions in response”). Following examination of the SAML response from logs, DocuSign is telling me:
> [1] There are ... 2 values passed [in cn or commonName] – there should only be 1 value and it should be the one that matches exactly what’s set in DocuSign…
> [2] keep it simple, swap out the urn:oid and put the friendly name in its place, that should help
Setting aside the perverseness and glibness, is [2] even possible?
Can I release a SAML attribute without a Name, only a friendlyName?
Perhaps I am supposed to put their version of friendlyName into the Name?
David Bantz
U Alaska IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140730/8e7fd682/attachment-0001.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140730/8e7fd682/attachment-0001.bin
More information about the users
mailing list