off-topic help for Office 365

Paul Hethmon paul.hethmon at clareitysecurity.com
Wed Feb 17 16:46:10 EST 2016


Matthew,

Thanks for the blog links, my Google-fu had not found them.

On Feb 17, 2016, at 4:33 PM, Matthew Slowe <M.Slowe at kent.ac.uk<mailto:M.Slowe at kent.ac.uk>> wrote:

If you're doing ECP as well then the certificate you have on the HTTPS ECP endpoint needs to be trusted *and* has to match the certificate in your configured - therefore the certificate you use in the SAML assertion has to be a signed one (which then expires…)

I never did validate whether ECP worked or not with my first setup. I stopped at logging into O365 via Shib.

So, to make sure I understand, getting ECP to work requires the TLS certificate be trusted (so signed by a commercial CA) and that the exact same certificate be used to sign the SAML responses?

-----
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160217/ef17fdd7/attachment.html>


More information about the users mailing list