off-topic help for Office 365
Aaron Howell
aaron.howell at deakin.edu.au
Wed Feb 17 16:20:31 EST 2016
Well last time I had Office365 attached to Shibboleth IdP you didn't need a CA signed certificate. However due to lack of full support on all Office 365 applications at the time, we introduce ADFS into the mix as well.
Of note, ADFS also does not use a external CA signed certificates for SAML signing - although it does use our internal CA in AD to manage its certificates. But we don't publish the chain.
I remember an issue where we needed to firstly remove federated authentication before re-adding the new one. Or something like that - it was a few years ago.
Cheers,
Aaron
On 18 Feb 2016, at 7:39 AM, Paul Hethmon <paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>> wrote:
On Feb 17, 2016, at 3:32 PM, Brent Putman <putmanb at georgetown.edu<mailto:putmanb at georgetown.edu>> wrote:
+ Set-MsolDomainAuthentication <<<< -DomainName $dom -FederationBrandName $dom -Authentication Federated -PassiveLogOnUri $url -SigningCertificate $cert -IssuerUri $uri -ActiveLogOnUri $ecpUrl -LogOffUri $logouturl -PreferredAuthenticationProtocol SAMLP
+ CategoryInfo : OperationStopped: (:) [Set-MsolDomainAuthentication], MicrosoftOnlineException
+ FullyQualifiedErrorId : Microsoft.Online.Administration.Automation.InternalServiceException,Microsoft.Online.Administration.Automation.SetDomainAuthentication
At this point, you supply MS support with useless information as they are apparently unable or unwilling to look into their own systems to find a real cause.
Yeah, nothing useful there. You have no access to any logs on the service side? Maybe they really do only support a CA-issued cert for some reason, who knows. Or is there some sort of mismatch between the domain you are specifying in the call and the CN in the cert? Otherwise I have no suggestions.
I actually did have a mismatch on CN originally, but regenerated the cert to match them up.
What kills me is that I had it working on a different IdP last fall, all I did is try to move it to a new IdP. Both using the same version of Shib (2.4) and both installed/created the same.
-----
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
Important Notice: The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete it and any attachments immediately and advise the sender by return email or telephone.
Deakin University does not warrant that this email and any attachments are error or virus free.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160217/69f16193/attachment.html>
More information about the users
mailing list