[Ext] Re: WORKPLACE BY FACEBOOK integration
Bryan Wooten
bryan.wooten at utah.edu
Wed Nov 2 19:44:42 EDT 2016
Is this not what Dedra is doing?
http://www.cirrusidentity.com/gateway/
-Bryan
From: IAM David Bantz <dabantz at alaska.edu<mailto:dabantz at alaska.edu>>
Reply-To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Wednesday, November 2, 2016 at 5:26 PM
To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: [Ext] Re: WORKPLACE BY FACEBOOK integration
I was provided:
Audience URL https://www.facebook.com/company/1077798945674112
Recipient URL https://alaska.facebook.com/work/saml.php
ACS (Assertion Consumer Service) URL https://alaska.facebook.com/work/saml.php
I'm guessing Recipient is entityID
db
On Wed, Nov 2, 2016 at 3:22 PM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
> WORKPLACE BY FACEBOOK apparently deploys simpleSAML PHP / SAML 2.0
> for SSO but provides minimal documentation. No metadata or certificate, no
> attribute requirements, etc.
The bare minimum is the endpoint, if the implementation is broken and doesn't check Audience conditions. That's not per se a security hole unless they also don't check the Recipient attribute, but that takes some dedicated pen-testing to determine. I have done integrations that did not have an entityID and worked like that, though after reporting it I was able to get them to configure one (in their view, the audience to check for).
When in doubt, stick whatever the user identifier has to be in the NameID and see if it works, assuming you know the endpoint to create the metadata around.
It is less work to just experiment, which takes a few minutes, than worry about getting all the details right.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161102/9718aba9/attachment.html>
More information about the users
mailing list