Docusign SSO
Klingenstein, Nate
nklingenstein at calstate.edu
Mon Nov 28 21:00:18 EST 2016
Pedro,
Identity Provider Issuer which must match the issuer field
in any SAML assertions. Not to sure what this means. Is it
just the URL to my IDP?
They're looking for the entityID of your IdP. You'll find that at the top of idp.properties.
There isn't just one URL for your IdP. The most important URL's are your metadata location("here's information about how to talk to this IdP") and your entityID("this is this IdP's primary name"), neither of which has to be a URL, and they don't have to be related in any way.
InCommon is a very good example: your metadata is hosted at InCommon, but your entityID probably isn't in their namespace, and many older IdP's have URN's for entityID's, which aren't practically resolvable.
If I could change one thing in the world, "IdP URL" would mean "entityID" and metadata would be hosted there. Modern versions of Shibboleth by convention host metadata at /idp/shibboleth, but it's far from consistent, which makes it far from usable in existing large-scale use.
I'm pushing for more consistency here, but it's one of the most painful things in SAML to change. It gets one step harder for you to change it every time you share it like this.
Take care,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161129/d174c71b/attachment.html>
More information about the users
mailing list