Shibboleth ECP and Office 365

Matthew Slowe m.slowe at kent.ac.uk
Mon Jun 6 04:39:03 EDT 2016


On Wed, Jun 01, 2016 at 06:33:39PM +0000, Jonathan L Ocab wrote:
> My concern with this is that Microsoft indicated to us that they send
> the full userprincipalname. We did everything to log including
> wiresharking the traffic and seeing only the username portion of the
> UPN being sent in the traffic dump. I've contacted MS support
> regarding this issue and they claim we’re doing something to the UPN.
> 
> Am I missing something in the IDP and ECP configuration? I could just
> leave it be and just filter on samaccountname since everything is
> working. But are we actually receiving the full UPN and somehow
> munging up the UPN? If I curl the ECP endpoint with a UPN string in
> the username field, it comes through correctly (I see it in the
> extended access logs). 

Our Office365->Shib ECP link definitely only gets the local part of the
UPN.

You may find a blog post I wrote a few years ago about testing it
useful:

	http://blogs.kent.ac.uk/unseenit/simple-shibboleth-ecp-test/

-- 
Matthew Slowe | Server Infrastructure Officer
IT Infrastructure, Information Services, University of Kent
Room S21, Cornwallis South
Canterbury, Kent, CT2 7NZ, UK
Tel: +44 (0)1227 824265 

www.kent.ac.uk/is | @UnikentUnseenIT | @UKCLibraryIt
PGP: https://keybase.io/fooflington


More information about the users mailing list