Integration with a Simitive SP

Todd, James J.Todd at napier.ac.uk
Wed Sep 7 09:57:27 EDT 2016


Thanks, Scott. I know I answered my own questions but when a vendor who has dealt with integration with other Universities threw this at me, then told me to read the Shibboleth documentation I really started to doubt myself or my own sanity. Sanity restored.

James

-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 07 September 2016 14:42
To: Shib Users <users at shibboleth.net>
Subject: Re: Integration with a Simitive SP

On 9/7/16 4:31 AM, Todd, James wrote:
>
> Also, I'm hoping that my horror at being asked for my IdPs private key
> is justified.

You probably should be telling your bosses that any company that bad at this really shouldn't be trusted with your university's data. I've done that in a couple of cases.

> I was under the impression my IdP would encrypt the assertion with
> their public key which could only be decrypted by their private key.
> Even just for my own sanity I'm right, right?

Yes, that's how encryption with assymetric keys works generally.

> The vendor is now saying that *my* side of the bargain is holding up
> the project and I'm in no mood to get the blame for this!

If it makes you feel any better, this is pretty frequently what happens when one side is running Shibboleth and the other is using Ping but typically the roles are reversed. Probably doesn't make you feel any better but I had to get that off my chest.

-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
This message and its attachment(s) are intended for the addressee(s) only and should not be read, copied, disclosed, forwarded or relied upon by any person other than the intended addressee(s) without the permission of the sender. If you are not the intended addressee you must not take any action based on this message and its attachment(s) nor must you copy or show them to anyone. Please respond to the sender and ensure that this message and its attachment(s) are deleted.

It is your responsibility to ensure that this message and its attachment(s) are scanned for viruses or other defects. Edinburgh Napier University does not accept liability for any loss or damage which may result from this message or its attachment(s), or for errors or omissions arising after it was sent. Email is not a secure medium. Emails entering Edinburgh Napier University's system are subject to routine monitoring and filtering by Edinburgh Napier University.

Edinburgh Napier University is a registered Scottish charity. Registration number SC018373



More information about the users mailing list