Crafted url for Idp initiated sso that includes discovery service?

Ewing, Bill BEwing at utsystem.edu
Tue Jan 17 09:24:34 EST 2017


We have a vendor that is only supporting an IDP initiated sso connection to their app. This app will be accessed by several of our federated schools that make use of our centralized discovery service. I was wondering if there was a way to craft a link that inserts the discovery service into the process so we could use one link for all schools.

We used to have a link that worked with a previous SAML1 version of this portal and had such a link but am not sure if it would fall under the same circumstances as the new portal is SAML2 among other diferences.
https://idm.utsystem.edu/DiscoveryService/UT-System.ds?shire=https://sso.wtc.hcsctest.net/sso/RP&target=https://fdlportal.wtc.hcsctest.net/fdl/servlet/FimLoginServlet&providerId=https://sso.wtc.hcsctest.net

on a lark I tried swapping out the information from our new portals metadata with the above link
https://idm.utsystem.edu/DiscoveryService/UT-System.ds?shire=https://fedsso.hcsc.net/affwebservices/public/saml2assertionconsumer&target=https://groupadmins.hcsc.net/portal/#!/home&providerId=FEDSSOPRODSP

But when I use the new link I get a wayf error below. I wasn't sure the non web address entityid they are using could cause the wayf to not recognize it?

Discovery Service failure at (/DiscoveryService/UT-System.ds)

Could not locate SP identifier in parameters
Let me know if I'm even on the right track with this type of link or am I barking up the wrong tree?

Thanks,
Bill


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170117/14c6772c/attachment.html>


More information about the users mailing list