IdP 3.2.1 integration with Adobe/Okta

Domingues, Michael D michael-domingues at uiowa.edu
Wed Dec 27 12:26:33 EST 2017


Our Adobe / Okta integration is vanilla. The only non-default setting we run is to disable assertion encryption, but that (if I recall correctly) is just because our tenant hasn't been configured to support it.


Michael

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Luke Whittington <lwhittin at uvic.ca>
Sent: Wednesday, December 20, 2017 6:29:12 PM
To: users at shibboleth.net
Subject: Re: IdP 3.2.1 integration with Adobe/Okta

We're on IDP 3.3.1 and haven't had to specify a signing method. Are you signing your assertions?

Luke

On Wed, 2017-12-20 at 21:35 +0000, King, David wrote:

Hi everyone,



We have been trying to integrate our mostly vanilla Shibboleth IdP 3.2.1 with Adobe creative cloud (Okta being the SP provider).  We have worked through the non-standard IDs and the requirement of a emailAddress NameID.  However, we are still having a stumbling block with them that I did not see mentioned in the archives or the wiki.



They are now saying that we need to configure our IdP to send SHA1 signatures instead of SHA256.  Did other folks have this issue with Adobe/Okta?  If so, how did you resolve it?  If not, do you have a special relying-party configuration or did you edit the SP metadata?



Thanks in advance for the help,

David

--

Luke Whittington
Web Application Developer
Development Services, University of Victoria
lwhittin at uvic.ca<mailto:lwhittin at uvic.ca> - 250-472-5696
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171227/56d54df2/attachment.html>


More information about the users mailing list