Azure as IDP protecting multiple Shibboleth Apps- Cert error
Sean Flannery
sean.flannery at jwt.com
Tue Sep 19 22:38:18 EDT 2017
Hello,
I think the short version of this question is: in shibboleth SP, can you map multiple certs to a given IDP entity ID? I'm supposing not. Or maybe there is another solution....
This is my problem:
We have used Shibboleth SP for some time but recently we have been asked to protect some apps that use Azure as IDP.
It works fine for a single app, but this is the problem with multiple apps:
* Azure IDP generates metadata for each each app you want to protect. The metadata for an app contains a unique cert, but the same entityID is used for all metadata.
* when you import all the metadata and setup the multiple applications in Shibboleth- only one of the apps will work. The others will all fail because their certs don't align with what shibboleth expects for that (IDP's) entityID.
Does the problem make sense?
I wish you could customize the entityID at the application level in Azure (for its IDP functionality) as that would solve the problem, and make the relationship more clear (since each app has its own login rules it sort of makes sense), but that doesn't seem possible.
Any suggestions? I searched past questions and didn't seem to run into this problem but perhaps I've missed it.
Thanks for any help
Sean
This transmission is intended solely for the person or organization to whom it is addressed and it may contain privileged and confidential information. If you are not the intended recipient you should not copy, distribute or take any action in reliance on it. If you believe you received this transmission in error please notify the sender.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170920/8154208f/attachment-0001.html>
More information about the users
mailing list