Office 365 ECP Issues

Lalith Jayaweera ljayaweera at gmail.com
Mon Jul 17 21:49:27 EDT 2017


Thanks Scott,

We got basic Apache authentication (via SASL) on for ECP for now (which is
working) but failing in Idp level.

Regarding Auth flows, we have configured to use CAS in idp
(idp.authn.flows= Shibcas),

I have not done any other configuration in idp (3.3.x) with respect to
enabling ECP......However I remember we did for IdP 2.4.x.

Do we have to do any other configuration to ECP to enforce remote_user

Let me know


Also looking at logs I see empty attribute list entries, hence telling
attributes have not been resolved.

Thanks





On Mon, Jul 17, 2017 at 11:25 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > For Office365 web profile works with no issues, just that ECP profile
> does not
> > seem to work, certainly it hits the IdP, hence Apache authentication is
> > success and see entries in idp logs
>
> You shouldn't generally be using Apache to authenticate an ECP request.
>
> > and able to see below error in logs
>
> You posted no logs.
>
> In any case since the error is with authentication, the problem is likely
> there. If you're using the Password login flow for standard use cases, you
> should use it for ECP, get Apache out, and it should work. If you're using
> RemoteUser for both, that should work. Using both is probably not going to
> work without a lot of screwing around.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170718/f8e0b2a9/attachment-0001.html>


More information about the users mailing list