users Digest, Vol 65, Issue 9

Bin Han Bin.Han at concordia.ca
Thu Nov 3 11:56:22 EDT 2016


Hi Scott:
Is there a patch for the "Sript Attributes definition" bug?
Thanks,
Bin

> One of our application is running on IDP V2 (yes, we do plan to move to V3),
That bug was fixed 2 years ago.

________________________________________
From: users <users-bounces at shibboleth.net> on behalf of users-request at shibboleth.net <users-request at shibboleth.net>
Sent: Wednesday, November 2, 2016 7:22 PM
To: users at shibboleth.net
Subject: users Digest, Vol 65, Issue 9

Send users mailing list submissions to
        users at shibboleth.net

To subscribe or unsubscribe via the World Wide Web, visit
        http://shibboleth.net/mailman/listinfo/users
or, via email, send a message with subject or body 'help' to
        users-request at shibboleth.net

You can reach the person managing the list at
        users-owner at shibboleth.net

When replying, please edit your Subject line so it is more specific
than "Re: Contents of users digest..."


Today's Topics:

   1. RE: Script Attributes definition (Cantor, Scott)
   2. WORKPLACE BY FACEBOOK integration (IAM David Bantz)
   3. RE: WORKPLACE BY FACEBOOK integration (Cantor, Scott)


----------------------------------------------------------------------

Message: 1
Date: Wed, 2 Nov 2016 17:08:23 +0000
From: "Cantor, Scott" <cantor.2 at osu.edu>
To: Shib Users <users at shibboleth.net>
Subject: RE: Script Attributes definition
Message-ID:
        <9846A6064BD102419D06814DD0D78DE112A811AE at CIO-TNC-D2MBX02.osuad.osu.edu>

Content-Type: text/plain; charset="us-ascii"

> One of our application is running on IDP V2 (yes, we do plan to move to V3),

That bug was fixed 2 years ago.

-- Scott



------------------------------

Message: 2
Date: Wed, 2 Nov 2016 15:17:35 -0800
From: IAM David Bantz <dabantz at alaska.edu>
To: "users at shibboleth.net" <users at shibboleth.net>
Subject: WORKPLACE BY FACEBOOK integration
Message-ID:
        <CAJ9XvwEKyCns_qvNZfUevtaFHnnCm4wTxo+vML-Z4BLpXuZ9Jw at mail.gmail.com>
Content-Type: text/plain; charset="utf-8"

WORKPLACE BY FACEBOOK apparently deploys simpleSAML PHP / SAML 2.0 for SSO
but provides minimal documentation. No metadata or certificate, no
attribute requirements, etc.

If any of you have this service relying on Shibb for SSO and would be
willing to provide the benefit of your experience, I will be grateful.

David Bantz

U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161102/dfc49f56/attachment-0001.html>

------------------------------

Message: 3
Date: Wed, 2 Nov 2016 23:22:48 +0000
From: "Cantor, Scott" <cantor.2 at osu.edu>
To: Shib Users <users at shibboleth.net>
Subject: RE: WORKPLACE BY FACEBOOK integration
Message-ID:
        <9846A6064BD102419D06814DD0D78DE112A81566 at CIO-TNC-D2MBX02.osuad.osu.edu>

Content-Type: text/plain; charset="utf-8"

> WORKPLACE BY FACEBOOK apparently deploys simpleSAML PHP / SAML 2.0
> for SSO but provides minimal documentation. No metadata or certificate, no
> attribute requirements, etc.

The bare minimum is the endpoint, if the implementation is broken and doesn't check Audience conditions. That's not per se a security hole unless they also don't check the Recipient attribute, but that takes some dedicated pen-testing to determine. I have done integrations that did not have an entityID and worked like that, though after reporting it I was able to get them to configure one (in their view, the audience to check for).

When in doubt, stick whatever the user identifier has to be in the NameID and see if it works, assuming you know the endpoint to create the metadata around.

It is less work to just experiment, which takes a few minutes, than worry about getting all the details right.

-- Scott



------------------------------

Subject: Digest Footer

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

------------------------------

End of users Digest, Vol 65, Issue 9
************************************


More information about the users mailing list