Integrating idp3 with cirqlive

Brandon McKean mckeanbs at jmu.edu
Tue Aug 22 08:18:29 EDT 2017


Hi Joseph,

I did this very thing recently. Where you want to look on the wiki is 
here: 
https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration

Specifically, the "Per-Profile Credential" example. It does require 
adding the information to credentials.xml as well.

Also keep in mind you'll need to adjust the metadata you give to WebEx 
and CirQlive, to reflect the new keypair you make.

-- 
Brandon McKean
IT / Systems
Linux Administrator
(540)568-4235

On 08/21/2017 09:54 PM, Joseph Fischetti wrote:
> I've been asked to look into integrating cirqlive with our existing 
> IDP 3 installation. Cirqlive adds a link between Sakai and webex sso.  
> During my research I found that cirqlive expects the private key of 
> our IDP so that it can sign the assertions that it sends to WebEx. 
> Obvious security concerns aside, when I reached out to cirqlive for 
> clarification, I received the following PDF in reply.  It seems that, 
> given architecture 1 (page 3), they feel that sharing the idp's 
> private key is okay. They also reference using separate keys for 
> different SPs, which as far as im aware, isn't possible with IDP 3. 
> https://documentation.cirqlive.com/manuals/SSO/Multi-Source_SAML_Authentication_with_WebEx_(MEETS).pdf 
> <https://urldefense.proofpoint.com/v2/url?u=https-3A__documentation.cirqlive.com_manuals_SSO_Multi-2DSource-5FSAML-5FAuthentication-5Fwith-5FWebEx-5F-28MEETS-29.pdf&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=-eCch-TyZt4YFZl-wx8BMnYAeOJcS3U-_JfYc5rIQlY&s=m8ewVPb9bdstoz4-yWc4xY8vWLD0vwrKWkx0PdFVXIg&e=> 
> Does anybody else have experience with this? Joseph Fischetti Linux 
> System Administrator Marist College
>
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170822/7b59e88a/attachment.html>


More information about the users mailing list