off-topic help for Office 365
Michael O Holstein
michael.holstein at csuohio.edu
Thu Feb 18 09:16:53 EST 2016
>> So, to make sure I understand, getting ECP to work requires the TLS
>> certificate be trusted (so signed by a commercial CA) and that the exact
>> same certificate be used to sign the SAML responses?
> That is (was) my understanding, yes.
I'm not sure what the cause of this issue was, but I have this configured in an O365 tenant tenant with ~100k users, where I am using a self-signed certificate for SAML signing, and a different (commercial) certificate for SSL channel security.
It was a hassle to figure out (things like binary attributes out of AD) but in hindsight there's nothing particularly esoteric about the configuration. You just import the Base64 encoded certificate via a Powershell cmdlet.
I should note that Microsoft has changed this recently (Q2/2015) as part of their "advanced authentication" project (ADAL). If you haven't tried it lately, maybe give it a second look.
Cheers,
Michael Holstein
Cleveland State University
More information about the users
mailing list