Integrating idp3 with cirqlive

Cantor, Scott cantor.2 at osu.edu
Wed Aug 23 09:16:05 EDT 2017


On 8/23/17, 8:00 AM, "users on behalf of Joseph Fischetti" <users-bounces at shibboleth.net on behalf of Joseph.Fischetti at marist.edu> wrote:

> For what it's worth, during my testing the hardest part of the whole integration was the auto provisioning. I had very few issues
> getting the user to simply authenticate as all webex really wanted was their username (email address). Auto provisioning was a 
> different story as, as already noted, webex wants certain attributes and does a very poor job outlining that.

Same comment as before...if nobody documents this in our wiki under IntegrationGuides, everybody else will have to do this. I can't do it, I haven't federated with WebEx.

> On top of everything else... we're also using the idp for authorization to webex. That is, we have a separate webex based on role,
> and I had to build attribute filter to release to the separate webexes based on the user's attributes. The major downside to this is
> that rather than receive any actual error message, webex just throws an error that a valid username wasn't found in the saml
> assertion. 

That's what the context-check interceptor flow is for.

-- Scott





More information about the users mailing list