Docusign
Klingenstein, Nate
nklingenstein at calstate.edu
Tue Aug 9 13:38:23 EDT 2016
Dunno what's going on, but these appear to be their docs, and if so, "it could be anything and it's more likely the difference was in whoever set up your DocuSign account."
https://www.docusign.com/supportdocs/ndse-admin-guide/Content/identity-providers.htm
> On Aug 9, 2016, at 9:56 AM, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu> wrote:
>
>> 2. They require a "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
> NameID, and they mean it. The identifier must be persistent because they don't allow renames.
>
> That was not the case for our Shib IdP -> DocuSign integration. DocuSign configured the SP to request a urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified formatted NameID, which we then generate in the conf/saml-nameid.xml, using the uid attribute value. Next, in the conf/relying-party.xml, we wired a custom profile to change the nameIDFormatPrecedence property so that the "unspecified" format is first up, and then a relying party override just for the docusign to use the custom profile without assertion encryption.
>
> The result is that the NameID that Docusign is provisioning our user accounts with is a plain-text uid.
>
> Josh
>
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Andrew Morgan
> Sent: Monday, August 8, 2016 7:20 PM
> To: Shib Users <users at shibboleth.net>
> Subject: Re: Docusign
>
> On Mon, 8 Aug 2016, IAM David Bantz wrote:
>
>> DocuSign is a net+ service provider, and the I2 site lists 15
>> subscribing institutions (
>> http://www.internet2.edu/products-services/cloud-services-applications
>> /docusign/docusign-subscribers/
>> ).
>>
>> I'm hoping one or more of those 15 is represented here, and would be
>> willing to share working IdPconfiguration. (When I last looked, the
>> only option I could find was a less-than-robust proxy or relay through
>> a third party vendor. I'm hoping for a direct integration between our
>> Shibboleth IdP and Docusign.)
>>
>> David Bantz
>> UAlaska
>
> David,
>
> *This OSU* has setup our IDP with Docusign in their demo environment.
>
> A few things to note:
>
> 1. They do not consume nor publish metadata in InCommon. They have an instance-specific entityID. I asked them to publish their metadata. They said they're working on it. You should bug them too.
>
> 2. They require a "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
> NameID, and they mean it. The identifier must be persistent because they don't allow renames.
>
> 3. Turn encryption off. They don't support it.
>
> 4. If you select Signed Requests, they have a bug that will always do a POST, so make sure you put a POST endpoint in for the URL.
>
> I think that's it. If you run into trouble, I can share our working config.
>
> Andy
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list