SAManage with Shibboleth 3?
Tom Scavo
trscavo at gmail.com
Thu Apr 19 14:33:32 EDT 2018
On Thu, Apr 19, 2018 at 4:46 AM, Mark Cairney <Mark.Cairney at ed.ac.uk> wrote:
>
> Just to confirm that it is working satisfactorily now.
Okay, that's great to hear. For the archives (and for my own
interest), there are still some unanswered questions.
> The hack...to give the
> application a more "user friendly" domain name a CNAME to it's "real"
> FQDN was set up. Therefore the application still "thinks" it's using
> it's real FQDN (according to it's internal metadata anyway).
Looking at the AuthnRequest you posted earlier, I see that
AssertionConsumerServiceURL='https://desk.ei.ed.ac.uk/saml/edin'
so the application apparently knows about your CNAME. How did you
configure the SP to use this particular AssertionConsumerServiceURL?
> To work around this I added an additional ACS entry with the
> "user-friendly" FQDN in it in my local metadata. Not pretty but it works.
That explains why you took a snapshot of their published metadata but
it doesn't explain how the SP is able to formulate the desired
AuthnRequest.
More importantly, what caused the NameID issues you reported earlier
and how did you resolve them? The published metadata [1] has a
<md:NameIDFormat> element. Did your snapshot have such an element all
along or did you add one recently (after Peter's recommendation)?
Basically, what did you do to resolve your NameID issues?
Thanks,
Tom
[1] https://edin.samanage.com/saml/metadata
More information about the users
mailing list