DocuSign SSO issues on Dev environment.
IAM David Bantz
dabantz at alaska.edu
Wed Nov 30 17:36:28 EST 2016
My IdP - DocuSign integration uses nameid-format unspecified. Sorry, it is
required.
In the request:
<samlp:NameIDPolicy AllowCreate="true"
> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"/>
In the response:
<saml2:Subject>
> <saml2:NameID
>
> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
> NameQualifier="urn:mace:incommon:alaska.edu"
> SPNameQualifier="
> https://account-d.docusign.com/organizations/dc41b1e0-5bbd-4859-be88-c28699bc57d2/saml2
> ">30459959</saml2:NameID>
> <saml2:SubjectConfirmation
> Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
> <saml2:SubjectConfirmationData Address="10.5.0.58"
> InResponseTo="_16bc9df9-e0e3-4592-a0e0-70ab3a244197"
> NotOnOrAfter="2016-11-30T22:39:28.376Z" Recipient="
> https://account-d.docusign.com/organizations/dc41b1e0-5bbd-4859-be88-c28699bc57d2/saml2/login
> "/>
> </saml2:SubjectConfirmation>
On Wed, Nov 30, 2016 at 1:11 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 11/30/16, 4:57 PM, "users on behalf of Andrew Morgan" <
> users-bounces at shibboleth.net on behalf of morgan at orst.edu> wrote:
> > Docusign requires a SAML Persistent NameID.
>
> Really? That's unusual. I did speak to them when they were designing the
> new platform, and gave them some advice, that certainly wasn't the advice I
> gave though.
>
> I guess I'm going to have trouble when they want us to move to it.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161130/2f5ab2a8/attachment.html>
More information about the users
mailing list