Integration with a Simitive SP

Todd, James J.Todd at napier.ac.uk
Wed Sep 7 04:31:23 EDT 2016


Morning everyone. Apologies for the X-post.

I'm not running a Shibboleth IdP, but I am having some issues with a vendor and their Shibboleth SP. Also I'm hoping that some other institutions may have come across Simitive before and also I don't think I'm dealing with a Shibboleth specific problem here, more a problem with a vendor.

Basically I'm trying to integrate my PingFederate IdP with Simitive (cloud hosted HR solution provider). It's been an odd experience so far.

First up I asked if I could have their metadata so I could use that to create the trust on my side. They said they "didn't publish metadata". Odd, but fair enough. So I asked for some details like an EntityID, ACS endpoints and so on so I could do it manually. They then sent me a shibboleth2.xml file and told me it was their metadata. Clearly this isn't the case and didn't contain any of the data I needed. Anyway, we got past that and I manually created a trust on my side with mostly "best guess" efforts (like assuming the AssertionConsumerService endpoints). I then sent them my metadata with public key.

Then an odd thing happened: they asked for my IdP's private key which I'm certainly in no mood to give out. They sent me a link to the Shibboleth documentation claiming this was necessary; I read the documentation and came to a whole different conclusion.

I know other Universities have used Simitive and done so via SAML, so I'm hoping that someone else has dealt with them before and I wonder if your encounters were as messy?

Also, I'm hoping that my horror at being asked for my IdPs private key is justified. I was under the impression my IdP would encrypt the assertion with their public key which could only be decrypted by their private key. Even just for my own sanity I'm right, right? The vendor is now saying that *my* side of the bargain is holding up the project and I'm in no mood to get the blame for this!

Cheers - and sorry for the long early morning email!
James

James Todd
Data Centre & Operations Analyst

Data Centre & Operations
Information Services
Edinburgh Napier University
Craiglockhart Campus
Edinburgh
EH12 1DJ

Tel No:  0131 455 4313
Email:    j.todd at napier.ac.uk
Twitter: @EdNapITSupport<https://twitter.com/EdNapITSupport> / @EdNapLib<https://twitter.com/EdNapLib>










This message and its attachment(s) are intended for the addressee(s) only and should not be read, copied, disclosed, forwarded or relied upon by any person other than the intended addressee(s) without the permission of the sender. If you are not the intended addressee you must not take any action based on this message and its attachment(s) nor must you copy or show them to anyone. Please respond to the sender and ensure that this message and its attachment(s) are deleted.

It is your responsibility to ensure that this message and its attachment(s) are scanned for viruses or other defects. Edinburgh Napier University does not accept liability for any loss or damage which may result from this message or its attachment(s), or for errors or omissions arising after it was sent. Email is not a secure medium. Emails entering Edinburgh Napier University's system are subject to routine monitoring and filtering by Edinburgh Napier University.

Edinburgh Napier University is a registered Scottish charity. Registration number SC018373

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160907/353e2823/attachment.html>


More information about the users mailing list