Box.net integration with shib 2.x
Rich Graves
rgraves at carleton.edu
Thu Jun 11 12:36:12 EDT 2015
Rob Gorrell:
> Examples can be found on the Box Net+ wiki entry: .../NetPlusIDG/BoxIDG
Yeah, that's where I found out about https://services.box.com/sp
They have asked me what key they should use for encryption. I thought I was encrypting my assertions to their key that they publish in their metadata. Am I confused, or are they, or both? What I currently get from https://sso.services.box.net/sp/ACS.saml2 is
Error - Single Sign-On
Unexpected exception occurred in Response Handling: No decryption key to decrypt the assertion.
Partner: urn:mace:incommon:carleton.edu
Target Resource: https://app.box.com/sso/ping_federate
They are apparently using https://services.box.com/sp as their entityID and I am getting their metadata from InCommon. I have no custom relying-party.
11:09:16.338 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:733] - Attempting to
encrypt NameID to relying party 'https://services.box.com/sp'
11:09:16.341 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:572] - Determining if
SAML assertion to relying party 'https://services.box.com/sp' should be signed
11:09:16.341 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:653] - IdP relying pa
rty configuration 'default' indicates to sign assertions: false
11:09:16.341 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:660] - Entity metadat
a for relying party 'https://services.box.com/sp 'indicates to sign assertions: false
11:09:16.341 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:274] - Attempting to
encrypt assertion to relying party 'https://services.box.com/sp'
11:09:16.342 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:279] - Assertion to b
e encrypted is:
[saml encoded]
11:09:16.343 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:796] - Encoding response to SAML request Vw1VPie58oQquj-sj6YnvfalIx0 from relying party https://services.box.com/sp
11:09:16.355 - INFO [Shibboleth-Audit:1028] - 20150611T160916Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|Vw1VPie58oQquj-sj6YnvfalIx0|https://services.box.com/sp|urn:mace:shibboleth:2.0:profiles:saml2:sso|urn:mace:incommon:carleton.edu|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|**|rgraves|duo|uid,eduPersonPrincipalName,transientId,surname,givenName,email,organizationalUnit,|**|
More information about the users
mailing list