iOS + Adfs + Shibboleth IDP
Cantor, Scott
cantor.2 at osu.edu
Wed Apr 8 21:35:22 EDT 2015
On 4/9/15, 1:03 AM, "Rhian Resnick" <rresnick at fau.edu> wrote:
>Evening,Our ADFS and Shibboleth integration saga continues. Our users are
>reporting issues using iOS and Android Office 365 (word, excel, etc) when
>connecting to ADFS and we are receiving the
> following error in the ADFS log.
Can you describe where Shibboleth fits into any of that, and what role
ADFS is playing? I'm going to guess ADFS is somewhere in the middle and
it's forwarding to Shibboleth for authentication.
>
>Issue 1: “Unknown Auth method” message when you try to sign in to an
>Office app for iOS or Mac
Is that the error you're getting?
>This error can occur in a topology where an enterprise has federated an
>AD FS server with Azure Active Directory for signing in to Office 365,
>and further federated the AD FS server with another non-Microsoft
>federation server such as Shibboleth. When Mac and iOS Office
>applications sign in, Azure Active Directory sends a parameter in the
>sign-in request to AD FS that requests forms authentication. When AD FS
>relays this request to the non-Microsoft federation server, it may be
>unable to interpret this parameter and it may display an error to the
>user, even before they are asked to sign in.
I can only go by what that literally says, and it seems to say that they
are attaching an illegal parameter not defined in SAML, which of course
would be a bug (theirs).
Maybe you could trace it in the server access log on the IdP, if it's a
redirect anyway. We can probably identify the bug if there's an example to
look at.
-- Scott
More information about the users
mailing list