Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.

Peter Schober peter.schober at univie.ac.at
Sat Jul 18 05:05:47 EDT 2015


* Cantor, Scott <cantor.2 at osu.edu> [2015-07-18 01:01]:
> Putting 2 and 2 together, I'm going to guess that the reason the
> metadata's wrong *and* has endpoints that make no sense is that you
> didn't actually create metadata for this SP, you copied metadata
> from an example for Shibboleth and just used it unchanged. You can't
> do that.

And I already created (what I think should be) complete and correct
metadata for that SP, earlier in this thread.
(And no, I'm not looking up the URL from the archives and I won't
repeat any of it here.)

> And to head off the next round, that's not enough. If the SP has a
> decryption key, then you need to put it in the metadata
> appropriately for the IdP to consume. If it doesn't, which is
> likely, then you need to turn off encryption, probably by creating
> or extending a RelyingParty override in the IdP configuration.

David B. and me also created complete copy&paste configuration for
the OP to configure just that.

(Not to mention figure out what his own IDP's entityID is, what the
SP's entityID is, what the SPs endpoints are, etc.)

It's all in the archives (including previous pointers to the archive).
-peter


More information about the users mailing list