Microsoft Azure + AD FS 3 + Shibboleth IdP v3
David Sanchez Herrero
david.krusty at gmail.com
Wed Feb 24 06:30:38 EST 2016
Hi again,
Thanks to all for your replies.
The suggested documentation was read and used to configure this scenario,
but due to the different software versions, we found some problems/erratas.
We workaround them, but maybe they are causing the problems.
There are no errors in the web browser. After authenticating in the
Shibboleth login page, the browser is redirected to the Office 365 login
page agaín, and that's all.
We are going to review again the AD FS 3 side using the suggested
documentation, even the parts related to AD FS 2.
Apart from this, two questions:
- The "Azure AD Connect" tool to deploy the AD FS and federate your domain,
installs a WAP (Web Application Proxy) server that is the intermediary
between AD FS 3 and the cloud. Maybe Shibboleth must talk with this WAP
server and not to AD FS 3 directly. What do you think about this?
- The only error/warning message in the logs is:
2016-02-23 13:06:08,011 - WARN
[net.shibboleth.idp.authn.impl.AttributeSourcedSubjectCanonicalization:146]
- Profile Action AttributeSourcedSubjectCanonicalization: No attributes
found, canonicalization not possible
Do you consider relevant this warning?
Thanks in advance, David.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160224/3ca8ec4e/attachment-0001.html>
More information about the users
mailing list