[Ext] Re: WORKPLACE BY FACEBOOK integration

Domingues, Michael D michael-domingues at uiowa.edu
Thu Nov 3 08:56:44 EDT 2016


Pretty sure this is the reverse. The Cirrus gateway (someone hop in and correct me if I'm wrong) allows campuses to use Social Login (Facebook, etcetera) and tie it in to their on-premise IAM environment. Workplace by Facebook is much like Microsoft's Yammer, in that it's a social network for the workplace (in so far as that's a thing), which acts as an SP, with the ability to use federated identities from campus IdPs for login.


________________________________
From: users <users-bounces at shibboleth.net> on behalf of Bryan Wooten <bryan.wooten at utah.edu>
Sent: Wednesday, November 2, 2016 6:44 PM
To: Shib Users
Subject: Re: [Ext] Re: WORKPLACE BY FACEBOOK integration

Is this not what Dedra is doing?

http://www.cirrusidentity.com/gateway/

-Bryan

From: IAM David Bantz <dabantz at alaska.edu<mailto:dabantz at alaska.edu>>
Reply-To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Wednesday, November 2, 2016 at 5:26 PM
To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: [Ext] Re: WORKPLACE BY FACEBOOK integration

I was provided:

Audience URL https://www.facebook.com/company/1077798945674112

Recipient URL https://alaska.facebook.com/work/saml.php

ACS (Assertion Consumer Service) URL https://alaska.facebook.com/work/saml.php

I'm guessing Recipient is entityID

db

On Wed, Nov 2, 2016 at 3:22 PM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
> WORKPLACE BY FACEBOOK apparently deploys simpleSAML PHP / SAML 2.0
> for SSO but provides minimal documentation. No metadata or certificate, no
> attribute requirements, etc.

The bare minimum is the endpoint, if the implementation is broken and doesn't check Audience conditions. That's not per se a security hole unless they also don't check the Recipient attribute, but that takes some dedicated pen-testing to determine. I have done integrations that did not have an entityID and worked like that, though after reporting it I was able to get them to configure one (in their view, the audience to check for).

When in doubt, stick whatever the user identifier has to be in the NameID and see if it works, assuming you know the endpoint to create the metadata around.

It is less work to just experiment, which takes a few minutes, than worry about getting all the details right.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161103/f4b1b9bc/attachment.html>


More information about the users mailing list