Shibboleth ECP and Office 365
Matthew Slowe
m.slowe at kent.ac.uk
Mon Jun 6 04:39:03 EDT 2016
On Wed, Jun 01, 2016 at 06:33:39PM +0000, Jonathan L Ocab wrote:
> My concern with this is that Microsoft indicated to us that they send
> the full userprincipalname. We did everything to log including
> wiresharking the traffic and seeing only the username portion of the
> UPN being sent in the traffic dump. I've contacted MS support
> regarding this issue and they claim we’re doing something to the UPN.
>
> Am I missing something in the IDP and ECP configuration? I could just
> leave it be and just filter on samaccountname since everything is
> working. But are we actually receiving the full UPN and somehow
> munging up the UPN? If I curl the ECP endpoint with a UPN string in
> the username field, it comes through correctly (I see it in the
> extended access logs).
Our Office365->Shib ECP link definitely only gets the local part of the
UPN.
You may find a blog post I wrote a few years ago about testing it
useful:
http://blogs.kent.ac.uk/unseenit/simple-shibboleth-ecp-test/
--
Matthew Slowe | Server Infrastructure Officer
IT Infrastructure, Information Services, University of Kent
Room S21, Cornwallis South
Canterbury, Kent, CT2 7NZ, UK
Tel: +44 (0)1227 824265
www.kent.ac.uk/is | @UnikentUnseenIT | @UKCLibraryIt
PGP: https://keybase.io/fooflington
More information about the users
mailing list