off-topic help for Office 365

Paul Hethmon paul.hethmon at clareitysecurity.com
Wed Feb 17 15:39:14 EST 2016


On Feb 17, 2016, at 3:32 PM, Brent Putman <putmanb at georgetown.edu<mailto:putmanb at georgetown.edu>> wrote:


+ Set-MsolDomainAuthentication <<<<  -DomainName $dom -FederationBrandName $dom -Authentication Federated  -PassiveLogOnUri $url -SigningCertificate $cert -IssuerUri $uri -ActiveLogOnUri $ecpUrl -LogOffUri $logouturl -PreferredAuthenticationProtocol SAMLP
    + CategoryInfo          : OperationStopped: (:) [Set-MsolDomainAuthentication], MicrosoftOnlineException
    + FullyQualifiedErrorId : Microsoft.Online.Administration.Automation.InternalServiceException,Microsoft.Online.Administration.Automation.SetDomainAuthentication

At this point, you supply MS support with useless information as they are apparently unable or unwilling to look into their own systems to find a real cause.



Yeah, nothing useful there. You have no access to any logs on the service side? Maybe they really do only support a CA-issued cert for some reason, who knows.  Or is there some sort of mismatch between the domain you are specifying in the call and the CN in the cert?  Otherwise I have no suggestions.

I actually did have a mismatch on CN originally, but regenerated the cert to match them up.

What kills me is that I had it working on a different IdP last fall, all I did is try to move it to a new IdP. Both using the same version of Shib (2.4) and both installed/created the same.

-----
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160217/b6870e8c/attachment.html>


More information about the users mailing list