ADFS 2 as Shib Proxy
Young, Darren
Darren.Young at chicagobooth.edu
Thu Aug 31 16:07:20 EDT 2017
>> Yeah, let¹s just say that¹s not a supportable option (putting local
>>school
>> addresses into the central LDAP server). Won¹t go into the details
>>on-list.
>
>Had to be suggested.
>
>My suggestion might not have been clear, but what I was trying to say was
>that rather than build claim rules to turn SAML attributes into MS
>attributes, you could just configure the IdP to encode them as MS
>attributes. The claim language in ADFS is both horrid, but more to the
>point undocumented in any real sense. But perhaps that's a problem due to
>what Dropbox expects to get not matching what ADFS would send it.
Horrid is one word to use for those claims rules, I have others I won¹t
use in public.
Dropbox basically needs nameID to be the value of a user¹s mail attribute
in our AD here. And that can be quite different that any data the campus
Shib would have in it.
I¹ve tried all sorts of combinations of rules in ADFS and haven¹t had
*any* decent luck, rather than spend 2 weeks on the phone with Microsoft
Premier Support I¹d rather just pay someone to get it done.
>
More information about the users
mailing list