Integrating idp3 with cirqlive
Cantor, Scott
cantor.2 at osu.edu
Wed Aug 23 09:16:05 EDT 2017
On 8/23/17, 8:00 AM, "users on behalf of Joseph Fischetti" <users-bounces at shibboleth.net on behalf of Joseph.Fischetti at marist.edu> wrote:
> For what it's worth, during my testing the hardest part of the whole integration was the auto provisioning. I had very few issues
> getting the user to simply authenticate as all webex really wanted was their username (email address). Auto provisioning was a
> different story as, as already noted, webex wants certain attributes and does a very poor job outlining that.
Same comment as before...if nobody documents this in our wiki under IntegrationGuides, everybody else will have to do this. I can't do it, I haven't federated with WebEx.
> On top of everything else... we're also using the idp for authorization to webex. That is, we have a separate webex based on role,
> and I had to build attribute filter to release to the separate webexes based on the user's attributes. The major downside to this is
> that rather than receive any actual error message, webex just throws an error that a valid username wasn't found in the saml
> assertion.
That's what the context-check interceptor flow is for.
-- Scott
More information about the users
mailing list