Microsoft Azure + AD FS 3 + Shibboleth IdP v3
Aaron Howell
aaron.howell at deakin.edu.au
Tue Feb 23 14:06:41 EST 2016
I haven't gotten IdPv3 up and running yet.
But really I can't see it being that different to setup than the notes here: https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop
Most of the configuration in that doco was on the ADFS side - not the Shibboleth side (shibboleth only needed metadata and attribute-release). I believe it's still the same SAML version between IdPv2 and v3 - so that should not cause problems.
On 24 Feb 2016, at 12:50 AM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
I order to do this you need to configure a proxy SP in front of your
shib IDP and configure your ADFS to trust that proxy SP. I'm not sure
if shib v3 supports SAML authentication (i.e has a proxy module) but
it should not be impossible.
No, other way around. If they want to use Shibboleth as the IdP and ADFS as the proxy hop, ADFS is just an SP, nothing unusual about it.
There is nothing provided here for anybody to go on. If you don't understand the logs, you can ask a specific question, but if your problem is ADFS' lack of logging or debugging, well, you know where Microsoft lives.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
Important Notice: The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete it and any attachments immediately and advise the sender by return email or telephone.
Deakin University does not warrant that this email and any attachments are error or virus free.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160223/8a40f0fd/attachment.html>
More information about the users
mailing list