Integration with Zendesk SP

Hwei Chan hwei at nextidea.co.nz
Mon Apr 10 09:38:55 EDT 2017


On the Shib side of things, I had to:

* fix the Zendesk metadata to set https://accountname.zendesk.com as the
entityID
* generate NameID as emailAddress
* set idp.encryption.optional = true in idp.properties
* release the standard displayName and mail (not sure if this is required)
attributes
* create a basic "role" attribute which maps to one of Zendesk's roles, ie,
end-user, agent or admin (though you probably don't need this if you're
happy to use the default of end-user)

I think that probably does the trick.

On 11 April 2017 at 01:24, Peter Schober <peter.schober at univie.ac.at> wrote:

> * Hwei Chan <hwei at nextidea.co.nz> [2017-04-10 14:16]:
> > Zendesk is now working with Shibboleth. Seems like I needed to enable
> SAML
> > SSO for both "Admin & Agents" and "End-users". Previously, I had enabled
> it
> > for "Admin & Agents" only.
>
> Any findings relevant to Shib? E.g.
> Did you need to send the email-type NameID? Or is sending transients
> (or nothing) OK, too?
> Did you have to create attributes with "basic" names?
> Any required attributes?
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170411/e2fed9c6/attachment.html>


More information about the users mailing list