iOS + Adfs + Shibboleth IDP
Kevin Foote
kpfoote at uoregon.edu
Wed Apr 8 23:40:26 EDT 2015
A large thanks from those following close in your footsteps.
- sent from mobile
> On Apr 8, 2015, at 8:14 PM, Rhian Resnick <rresnick at fau.edu> wrote:
>
> Scott and All,
>
> We have confirmed this works! We are writing up the settings as recommended additions to the Shibboleth ADFS integration page. Microsoft also needs to update the document since the fix was so minor.
>
>
> Rhian Resnick
> Assistant Director Middleware and HPC
> Office of Information Technology
>
> Florida Atlantic University
> 777 Glades Road, CM22, Rm 218
> Boca Raton, FL 33431
> Phone 561.297.2647
> Fax 561.297.0222
>
>
> ________________________________________
> From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Rhian Resnick <rresnick at fau.edu>
> Sent: Wednesday, April 08, 2015 10:45 PM
> To: Shib Users
> Subject: Re: iOS + Adfs + Shibboleth IDP
>
> Thank you! I will add that to the idp.
>
> Rhian Resnick
> Assistant Director Middleware and HPC
> Office of Information Technology
>
> Florida Atlantic University
> 777 Glades Road, CM22, Rm 218
> Boca Raton, FL 33431
> Phone 561.297.2647
> Fax 561.297.0222
>
>
> ________________________________________
> From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
> Sent: Wednesday, April 08, 2015 10:44 PM
> To: Shib Users
> Subject: Re: iOS + Adfs + Shibboleth IDP
>
> On 4/9/15, 1:51 AM, "Rhian Resnick" <rresnick at fau.edu> wrote:
>
>
>>
>> Here is a trace from the access log and idp-audit.log
>> 10.19.48.201 - - [08/Apr/2015:21:49:27 -0400] "GET
>> /idp/profile/SAML2/Redirect/SSO?SAMLRequest=jZLditswEIVfxejelm1iOxaOISQUAr
>> vdkpRe9E6RRkRgS65GbnbffmWlgZZlQ%2b%2fEaH7Od2Y65OMwse3sL%2bYIv2ZAnxz2G6Jl2p
>> xhVVeFTFtRNunq3K7Tc9HUadOcq1KsVa2qmiQ%2fwKG2ZkPKLCfJAXGGg0HPjQ%2bhvKjSfJXm
>> 7fe8YKuWlVVWt%2bVPkuzDHG24j5UX7ydklCLaTPE5AzlTLSc6Oav0APS0fX4q6RGkdiA8PZ1e
>> SLKzBmGZMTvDLEeNzPARkHnBlnwW5DBxS2KzwQmEVhokSb5YJyDyboh3M5DkdRwMsmjE435BkL
>> fCDqTvIqi7lT4u4ojgFlDSL6CBk0uFEVSI%2bKYh4bcWgDToQd%2fRW%2fO%2bu%2b3ma2h52H
>> %2bzgxZvi%2fqRP8AusiJGwv5UTP0XfjsM9rpzwD3c6el9zp%2f1g4zmBIM9vPr759%2bx3RCY
>> jqD%2b37iPHqC4wMgxG7VwFq3ymbAjvSIt83xN8zocQNic9m%2bUh8nLU8RrGcFfrKRT6Hi1Tn
>> b0c3n9%2ffMTMPrx9Pt3&RelayState=704a1051-b4f9-4dc7-a1ce-85e217f52652
>> HTTP/1.1" 302 -
>
> That decodes fine, but it contains a RequestedAuthnContext class:
>
> http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/passw
> ord
>
> That's proprietary and not something your IdP will know how to fulfill
> unless you teach it to. That will basically fail the request.
>
>> 10.19.48.201 - - [08/Apr/2015:21:49:27 -0400] "GET /idp/AuthnEngine
>> HTTP/1.1" 302 -
>
> The process log ought to show it refusing to run any login handlers.
>
> So based on all of that, there's nothing buggy per se, but they're doing
> something you would have to accomodate.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list