WORKPLACE BY FACEBOOK integration
IAM David Bantz
dabantz at alaska.edu
Wed Nov 2 19:26:46 EDT 2016
I was provided:
Audience URL https://www.facebook.com/company/1077798945674112
Recipient URL https://alaska.facebook.com/work/saml.php
ACS (Assertion Consumer Service) URL
https://alaska.facebook.com/work/saml.php
I'm guessing Recipient is entityID
db
On Wed, Nov 2, 2016 at 3:22 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > WORKPLACE BY FACEBOOK apparently deploys simpleSAML PHP / SAML 2.0
> > for SSO but provides minimal documentation. No metadata or certificate,
> no
> > attribute requirements, etc.
>
> The bare minimum is the endpoint, if the implementation is broken and
> doesn't check Audience conditions. That's not per se a security hole unless
> they also don't check the Recipient attribute, but that takes some
> dedicated pen-testing to determine. I have done integrations that did not
> have an entityID and worked like that, though after reporting it I was able
> to get them to configure one (in their view, the audience to check for).
>
> When in doubt, stick whatever the user identifier has to be in the NameID
> and see if it works, assuming you know the endpoint to create the metadata
> around.
>
> It is less work to just experiment, which takes a few minutes, than worry
> about getting all the details right.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161102/48a8aa98/attachment.html>
More information about the users
mailing list