Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.

Cahill, Charles (GE Appliances) Charles.Cahill at ge.com
Mon Jun 1 11:52:05 EDT 2015


From: Cahill, Charles (GE Appliances)
Sent: Monday, June 01, 2015 11:29 AM
To: Shib Users
Subject: RE: Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.


Hey All:



              I appreciate the response.  I believe I am still totally confused on how to get my Shib IDP to communicate with PagerDuty.

              I did look at the PagerDuty docs and they have PingONE as a SAML integration option.  PingONE actually has PagerDuty

              listed in its application pull down for integration.  My problem here is that I don’t understand how to come up with some

              of the data PingONE creates.  Spefically the “Single Sign On” URL that it generates.



              http://www.pagerduty.com/docs/guides/pingone-sso-setup/



              This page will show how PingONE will auto generate the weird SSO URL.



              I have also been looking at trying to turn on Anonymous Relying Parties to see if this is a fix to my problem using

              this Wiki thread.   It still doesn’t seem to want to work.



Thanks,

Charles





-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Kevin Foote
Sent: Friday, May 29, 2015 12:48 PM
To: Shib Users
Subject: Re: Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.







> On May 29, 2015, at 9:01 AM, Cahill, Charles (GE Appliances) <Charles.Cahill at ge.com<mailto:Charles.Cahill at ge.com>> wrote:



>



>               I am having some major issues getting PagerDuty to talk to our Shibboleth IDP.



>               I am very confused about the fact that all PagerDuty asks for in its configurations is the



>               Shibboleth login page and cert info.  There is not metadata for me to retrieve and obviously



>               I am not installing the Shibboleth Service Provider in this case.  Does the IDP need to be set



>               To Anonymous Relying Party  and if so, I cannot find much documentation on how to get these



>               guys to talk.   Any help would be greatly appreciated.







Hi Charles,











Many of these ‘newish’ SaaS solutions do the bare minimum of getting you squared away with a SAML2 exchange. For the most part they want you to



take the parts of your idp-metadata.xml file and input them into their setup form.







I’ve never messed with pagerduty so milage-may-very on the below but, they have docs and you can basically follow the OneLogin or Ping docs.



(Follow the Ping doc)







Using Shib your SSO URL will be something to the effect of







https://urldefense.proofpoint.com/v2/url?u=https-3A__&d=AwIGaQ&c=IV_clAzoPDE253xZdHuilRgztyh_RiV3wUrLrDQYWSI&r=Ay4xjbXoe6YvlvYwTANr9ZsOm6cEXvasE-gwLIuoyN8&m=kHvMBRZNqjRwv-3Zh36qz4JOdcbO4Uq4cWbOFqgPEaw&s=dwsLqXRVNlBb8-Xu7MFdBRjfECkAOhILFVRmnAK2ddE&e= <yourIDP>/idp/profile/SAML2/POST/SSO







Your cert will be in your credentials directory or also found in your idp-metadata.xml file. You will most likely not have a SLO URL unless you have done something local.







For the RP registration you can mock up the metadata on your end .. or look at the ping doc and I think that should explain more..











--------



thanks



kevin.foote







--

To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150601/16878d12/attachment-0001.html>


More information about the users mailing list