Integration with Zendesk SP

Hwei Chan hwei at nextidea.co.nz
Sat Apr 8 18:54:30 EDT 2017


Hi Peter,

You're absolutely right! I updated the entityID for Zendesk to 
https://xxxxxx.zendesk.com and voila, I got the IdP login screen!

Thanks so much for your help so far!

Unfortunately, I still get an unauthenticated error back in Zendesk... 
so I'll need to dig further!
Maybe some missing mandatory attributes...

Regards,
Hwei

On 09/04/17 10:11, Peter Schober wrote:
> * Peter Schober <peter.schober at univie.ac.at> [2017-04-08 23:54]:
>> "No metadata returned" and "UnverifiedRelyingParty" means their
>> documentation is wrong, IMO. At least if you have configured their
>> SAML SP with an entityID of "xxxxxx.zendesk.com" (as I recall their
>> docs stating) but the request they send seems to come with an entityID
>> of "https://xxxxxx.zendesk.com", which is not the same thing (but
>> actually preferrable, as the latter is a valid URI).
> "Table 3" in https://support.zendesk.com/hc/en-us/articles/203663676
> is correct it seems (stating "https://your_subdomain.zendesk.com/" as
> the entityID to give your copy of their metadata) but their literal
> SAML 2.0 metadata document ("Here is the Zendesk SAML 2.0 metadata")
> isn't, as that starts with:
> <EntityDescriptor entityID="your_subdomain.zendesk.com"
> which is likely what you've used.
> -peter



More information about the users mailing list