Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.
Cahill, Charles (GE Appliances)
Charles.Cahill at ge.com
Thu Jun 11 15:42:09 EDT 2015
Pager Duty also sent me this. Which they don't seem to be much help in getting this configured.
While we couldn't tell you exactly how to make the changes, the following is the information you would need to configure Shibboleth with us.
Entity ID= "<subdomain>.pagerduty.com"
ACS URL = "https://<subdomain>.pagerduty.com/sso/saml/consume<https://%3csubdomain%3e.pagerduty.com/sso/saml/consume>"
We expect the NameID claim as a 1.1 format email address. Specifically, it will look something like this: <Subject><NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">matt at example.com<mailto:matt at example.com></NameID>
There's no need to encrypt the responses as they are sent over HTTPS.
Please let me know if you have any additional questions.
From: Cahill, Charles (GE Appliances)
Sent: Thursday, June 11, 2015 3:36 PM
To: 'users at shibboleth.net'
Subject: Re: Re: Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.
So I have made all of the changes Peter recommended in this thread.
http://shibboleth.net/pipermail/users/2015-June/021856.html
I still seem to be getting the below error:
15:25:32.777 [http-bio-8080-exec-10] DEBUG e.i.m.s.i.a.p.UsernamePasswordLoginServlet - Successfully authenticated user xxxxxxxx
15:25:32.778 [http-bio-8080-exec-10] DEBUG e.i.m.s.i.authn.AuthenticationEngine - Returning control to authentication engine
15:25:32.778 [http-bio-8080-exec-10] DEBUG e.i.m.s.idp.util.HttpServletHelper - LoginContext key cookie was not present in request
15:25:32.778 [http-bio-8080-exec-10] WARN e.i.m.s.i.authn.AuthenticationEngine - No login context available, unable to return to authentication engine
15:25:32.892 [http-bio-8080-exec-10] DEBUG e.i.m.s.idp.util.HttpServletHelper - LoginContext key cookie was not present in request
15:25:32.892 [http-bio-8080-exec-10] DEBUG e.i.m.s.idp.ui.ServiceContactTag - No relying party, nothing to display
May I inquire again into what the login URL is that I would be giving the 3rd party PagerDuty application or how it should be formatted?
I currently gave them this https://{$myidp}/idp/Authn/UserPassword<https://%7b$myidp%7d/idp/Authn/UserPassword>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150611/f6220dc9/attachment-0001.html>
More information about the users
mailing list