Manually Generate a SAML Response

Michael Dahlberg olgamirth at gmail.com
Wed Jun 21 15:04:08 EDT 2017


Thank you all very much for your assistance.

Nate:

Its not the actual AuthnRequest that I'm trying to generate but the SAML
response once the AuthnRequest is complete

Scott:

That worked ... or at least the SAML response wasn't returned.  Thanks!

Peter:

I would SO love to do that .  Unfortunately, the vendor says "no, you have
to do it this way".  The department that wants this SSO connection goes to
my boss and my boss says "do it".  I would really like to get to a point
where I can make some of these SPs jump through arbitrary "hoops", just
because I feel like it.

Michael:

You are correct.

Thanks again,
Mike

On Wed, Jun 21, 2017 at 8:56 AM, Domingues, Michael D <
michael-domingues at uiowa.edu> wrote:

> Based on the phrasing of the initial request, I'm about 90% confident that
> the vendor in question here is Photoshelter. If that's indeed the case,
> when integrating with them, we had success at Iowa by pushing back and
> insisting that they enable SP-initiated SSO and test things in the
> conventional manner.
>
>
> Michael, if this is the case, feel free to contact me off-list and I can
> provide some more details.
> ------------------------------
> *From:* users <users-bounces at shibboleth.net> on behalf of Peter Schober <
> peter.schober at univie.ac.at>
> *Sent:* Wednesday, June 21, 2017 5:45:56 AM
> *To:* users at shibboleth.net
> *Subject:* Re: Manually Generate a SAML Response
>
> * Michael Dahlberg <olgamirth at gmail.com> [2017-06-20 22:26]:
> > I have what I think is a unique problem.  I'm working with a SP that
> wants
> > to validate our IdP.  In so doing, they want us to POST a web document to
> > their test site which contains three fields: a base64 encoded SAML2
> > response, the base64 encoded version of our Shibboleth X509 cert, and our
> > entityId.
>
> Maybe just ask them to stop being silly, support SAML 2.0 Metadata (to
> learn your IDP's cert, among other things) and provide a way to
> actually test logins to their SP using your IDP, then they'll get all
> that anyway. Just a thought.
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170621/2aac0f6a/attachment-0001.html>


More information about the users mailing list