DocuSign SSO issues on Dev environment.

IAM David Bantz dabantz at alaska.edu
Wed Nov 30 17:36:28 EST 2016


My IdP - DocuSign integration uses nameid-format unspecified. Sorry, it is
required.

In the request:

    <samlp:NameIDPolicy AllowCreate="true"
> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"/>

In the response:

        <saml2:Subject>
>             <saml2:NameID
>
> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
>                 NameQualifier="urn:mace:incommon:alaska.edu"
> SPNameQualifier="
> https://account-d.docusign.com/organizations/dc41b1e0-5bbd-4859-be88-c28699bc57d2/saml2
> ">30459959</saml2:NameID>
>             <saml2:SubjectConfirmation
> Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
>                 <saml2:SubjectConfirmationData Address="10.5.0.58"
>                     InResponseTo="_16bc9df9-e0e3-4592-a0e0-70ab3a244197"
>                     NotOnOrAfter="2016-11-30T22:39:28.376Z" Recipient="
> https://account-d.docusign.com/organizations/dc41b1e0-5bbd-4859-be88-c28699bc57d2/saml2/login
> "/>
>             </saml2:SubjectConfirmation>


On Wed, Nov 30, 2016 at 1:11 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 11/30/16, 4:57 PM, "users on behalf of Andrew Morgan" <
> users-bounces at shibboleth.net on behalf of morgan at orst.edu> wrote:
> > Docusign requires a SAML Persistent NameID.
>
> Really? That's unusual. I did speak to them when they were designing the
> new platform, and gave them some advice, that certainly wasn't the advice I
> gave though.
>
> I guess I'm going to have trouble when they want us to move to it.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161130/2f5ab2a8/attachment.html>


More information about the users mailing list