SAML2 with WebMD
Walter Forbes Hoehn (wassa)
wassa at memphis.edu
Fri Apr 3 18:17:12 EDT 2015
I’m guessing that the SP metadata does not include a public key/certificate. This makes it impossible for the IdP to encrypt the response or assertion.
-Walter
> On Apr 3, 2015, at 4:21 PM, Koch, Ken <ken at wustl.edu> wrote:
>
> Here’s the log output. I do have a signing and encryption x509 in the metadata.
>
> 2015-04-03 16:19:01,998 - WARN [org.opensaml.xmlsec.impl.BasicEncryptionParametersResolver:221] - Validation failure: Failed to resolve both a data and a key encryption credential
> 2015-04-03 16:19:01,998 - WARN [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:343] - Profile Action PopulateEncryptionParameters: Resolver returned no EncryptionParameters
>
>
>
> -Ken
>
> From: Koch, Ken
> Sent: Friday, April 3, 2015 4:15 PM
> To: Shib Users
> Subject: RE: SAML2 with WebMD
>
> I believe I have everything configured. When I set assertionEncryption to false, the SAML token package looks good. However, when I set it to the default I no longer get a login prompt. Instead, the IDP redirects me straight to the target instead of prompting for AuthN. Ring any bells?
>
>
> -Ken
>
> From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Caskey, Paul
> Sent: Friday, April 3, 2015 3:32 PM
> To: Shib Users
> Subject: RE: SAML2 with WebMD
>
> We did SAML with WebMd a few years ago. And, yes we did IdP-initiated.
>
> Otherwise, I don’t recall anything special, other than bi-lateral metadata exchange (not through InCommon).
>
>
> From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Koch, Ken
> Sent: Friday, April 03, 2015 3:10 PM
> To: Shib Users
> Subject: SAML2 with WebMD
>
> Has anyone configured Shibboleth SAML2 with WebMD? We’re midway through the process and they’re strictly enforcing an IDP-initiated AuthN model only. I was wondering if anyone had any experience with that vendor.
>
> We don’t have any IDPUnsolicitedSSO right now and are mid-way in transition to IdPv3. From what I read, the IdPv2 docs still apply with no modifications to our 3.1.1 IdP?
>
> ____________________________________________________________
> Ken Koch | Sr. Engineer
> Information Services and Technology | Washington University in St. Louis
> 7425 Forsyth Blvd., Campus Box 1110 | St. Louis, MO 63105
> w 314-935-8315 | c 314-223-7256 | ken at wustl.edu
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list