Concur V3 configuration and RE: Single Sign On (SSO) no longer working

Cantor, Scott cantor.2 at osu.edu
Thu Mar 3 21:33:06 EST 2016


> I am very appreciative of the version 3 documentation.  For everything other
> than NameID I was able to understand its structure quickly from the
> documentation.    I think a large part of the NameID issue is having seen our
> V2 configuration first which has a bunch of ... strange things.

Did you read the notes on V2 compatibility at the bottom of the NameIDGeneration topic? I think it might answer some of your questions about the difference, but it's buried at the end a bit.

> That is why I
> have been trying whenever possible build the replacement the V3 way
> instead of carrying over these V2 configs any longer.

I really wasn't urging that, I'm just saying don't combine them and end up with a mess. I'm not being disingenuous, I'm about to upgrade here and I am *not* redoing my NameID generation initially because I don't need to, I need to upgrade and keep all the existing behavior before I worry about redoing that. The resolver is 100% compatible and it keeps doing all the things it did before, which means I don't need to test every last case.

I did redo my relying-party file, but if I were not the author of the new format or didn't need the new features yet, I wouldn't have even done that yet. But I don't use the relying-party settings to drive NameID formats, and that part isn't new. It wasn't the right way to do it before either. Most of my V2 overrides were because of encryption, and with the optional feature, all those go away anyway. We really need to advertise that particular change more.

-- Scott



More information about the users mailing list