SAManage with Shibboleth 3?
Mark Cairney
Mark.Cairney at ed.ac.uk
Fri Apr 20 07:25:18 EDT 2018
On 19/04/18 19:33, Tom Scavo wrote:
> On Thu, Apr 19, 2018 at 4:46 AM, Mark Cairney <Mark.Cairney at ed.ac.uk> wrote:
>>
>> Just to confirm that it is working satisfactorily now.
>
> Okay, that's great to hear. For the archives (and for my own
> interest), there are still some unanswered questions.
>
>> The hack...to give the
>> application a more "user friendly" domain name a CNAME to it's "real"
>> FQDN was set up. Therefore the application still "thinks" it's using
>> it's real FQDN (according to it's internal metadata anyway).
>
> Looking at the AuthnRequest you posted earlier, I see that
>
> AssertionConsumerServiceURL='https://desk.ei.ed.ac.uk/saml/edin'
>
> so the application apparently knows about your CNAME. How did you
> configure the SP to use this particular AssertionConsumerServiceURL?
>
I don't have direct access to the SP- I added the URL manually to my
local copy of the metadata to work around the issue. The metadata pulled
from the SP itself doesn't contain any reference to desk.ei.ed.ac.uk
>> To work around this I added an additional ACS entry with the
>> "user-friendly" FQDN in it in my local metadata. Not pretty but it works.
>
> That explains why you took a snapshot of their published metadata but
> it doesn't explain how the SP is able to formulate the desired
> AuthnRequest.
>
> More importantly, what caused the NameID issues you reported earlier
> and how did you resolve them? The published metadata [1] has a
> <md:NameIDFormat> element. Did your snapshot have such an element all
> along or did you add one recently (after Peter's recommendation)?
> Basically, what did you do to resolve your NameID issues?
The NameID was the easier of the 2 issues. I resolved it by adding the
entries in saml-nameid.xml. I also created a specific mail attribute in
attribute resolver for this SP which strictly isn't necessary but it
makes it explicit that the attribute exists purely to work with that SP.
(I consider, rightly or wrongly, any nameID wrangling at the IdP end as
working around broken SP behaviour)
The main reason I contacted the list was actually the signing behaviour.
My guess is that by not explicitly setting it to enabled or disabled
allows the 2 parties to agree it between themselves.
>
> Thanks,
>
> Tom
>
> [1] https://edin.samanage.com/saml/metadata
>
--
/****************************
Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh
Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk
PGP: 0x435A9621
*******************************/
The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.
More information about the users
mailing list