iOS + Adfs + Shibboleth IDP

Rhian Resnick rresnick at fau.edu
Wed Apr 8 23:14:34 EDT 2015


Scott and All,

We have confirmed this works! We are writing up the settings as recommended additions to the Shibboleth ADFS integration page. Microsoft also needs to update the document since the fix was so minor.


Rhian Resnick
Assistant Director Middleware and HPC
Office of Information Technology​

​Florida Atlantic University
777 Glades Road, CM22, Rm 218
Boca Raton, FL 33431
Phone 561.297.2647
Fax 561.297.0222
 ​ ​

________________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Rhian Resnick <rresnick at fau.edu>
Sent: Wednesday, April 08, 2015 10:45 PM
To: Shib Users
Subject: Re: iOS + Adfs + Shibboleth IDP

Thank you! I will add that to the idp.

Rhian Resnick
Assistant Director Middleware and HPC
Office of Information Technology​

​Florida Atlantic University
777 Glades Road, CM22, Rm 218
Boca Raton, FL 33431
Phone 561.297.2647
Fax 561.297.0222
 ​ ​

________________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Wednesday, April 08, 2015 10:44 PM
To: Shib Users
Subject: Re: iOS + Adfs + Shibboleth IDP

On 4/9/15, 1:51 AM, "Rhian Resnick" <rresnick at fau.edu> wrote:


>
>Here is a trace from the access log and idp-audit.log
>10.19.48.201 - - [08/Apr/2015:21:49:27 -0400] "GET
>/idp/profile/SAML2/Redirect/SSO?SAMLRequest=jZLditswEIVfxejelm1iOxaOISQUAr
>vdkpRe9E6RRkRgS65GbnbffmWlgZZlQ%2b%2fEaH7Od2Y65OMwse3sL%2bYIv2ZAnxz2G6Jl2p
>xhVVeFTFtRNunq3K7Tc9HUadOcq1KsVa2qmiQ%2fwKG2ZkPKLCfJAXGGg0HPjQ%2bhvKjSfJXm
>7fe8YKuWlVVWt%2bVPkuzDHG24j5UX7ydklCLaTPE5AzlTLSc6Oav0APS0fX4q6RGkdiA8PZ1e
>SLKzBmGZMTvDLEeNzPARkHnBlnwW5DBxS2KzwQmEVhokSb5YJyDyboh3M5DkdRwMsmjE435BkL
>fCDqTvIqi7lT4u4ojgFlDSL6CBk0uFEVSI%2bKYh4bcWgDToQd%2fRW%2fO%2bu%2b3ma2h52H
>%2bzgxZvi%2fqRP8AusiJGwv5UTP0XfjsM9rpzwD3c6el9zp%2f1g4zmBIM9vPr759%2bx3RCY
>jqD%2b37iPHqC4wMgxG7VwFq3ymbAjvSIt83xN8zocQNic9m%2bUh8nLU8RrGcFfrKRT6Hi1Tn
>b0c3n9%2ffMTMPrx9Pt3&RelayState=704a1051-b4f9-4dc7-a1ce-85e217f52652
>HTTP/1.1" 302 -

That decodes fine, but it contains a RequestedAuthnContext class:

http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/passw
ord

That's proprietary and not something your IdP will know how to fulfill
unless you teach it to. That will basically fail the request.

>10.19.48.201 - - [08/Apr/2015:21:49:27 -0400] "GET /idp/AuthnEngine
>HTTP/1.1" 302 -

The process log ought to show it refusing to run any login handlers.

So based on all of that, there's nothing buggy per se, but they're doing
something you would have to accomodate.

-- Scott

>
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list