Office 365 -> ADFS ->Shibboleth iOS problems?

Eric Kool-Brown kool at uw.edu
Wed Aug 17 18:02:30 EDT 2016


Hi Scott,

No, I don't know how the Apple mail app works but I presume that it is using the WS-Trust version of ECP or artifact binding. This is similar to how older versions of Outlook worked where the app itself prompts for creds and then sends them as part of session initiation (protected by SSL/TLS of course).

    Eric

> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor,
> Scott
> Sent: Wednesday, August 17, 2016 2:43 PM
> To: users at shibboleth.net
> Subject: Re: Office 365 -> ADFS ->Shibboleth iOS problems?
> 
> On 8/17/16 5:36 PM, Eric Kool-Brown wrote:
> >
> > We are running ADFS 2.0 so I would be surprised if it recognized the new
> > MS-PKAP header and acted on it, but perhaps this was added via an
> update.
> 
> Doesn't seem likely any other SAML IdP products would understand it either.
> 
> You mentioned OneDrive, and I seem to recall that it was mentioned as an
> outlying / non-functional part of the picture when I spoke to Microsoft
> recently, but the OP seemed to be saying all their apps there weren't
> working.
> 
> Since we're discussing it, can you explain to me how login from non-MS
> mail clients (e.g. Apple Mail on iOS) works if you federate with ADFS
> (with or without Shibboleth)?
> 
> I know with Shibboleth you probably would have to do the ECP proxy
> thing, but do they actually support this via WS-Trust with ADFS natively
> to avoid that?
> 
> -- Scott
> --
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net


More information about the users mailing list