Making a SP think it's talking to an ADFS server
Mr. Christopher Bland
chris at fdu.edu
Wed Jan 23 15:52:36 EST 2019
Hi All,
I have just been presented with interesting challenge. I have a department that is configuring a SP using a SAML implementation provided by Ellucian. Ellucian supports Shibboleth but logout functionality doesn’t work properly and can’t be customized. In working with Ellucian they say if we use ADFS we can customize the logout with redirect. Has anyone ever done something like this?
Looking at Ellucian’s ADFS docs with suggested transform rules I think masquerading my IDP as and ADFS server might be possible. However I am not sure if the attributes and assertions need to be formatted differently. I assume I can replace URLs ADFS endpoints with Shibboleth assertion URLs. They also require the use or SHA-1 as a hash algorithm, not sure about this one. Lastly for logout and redirect they want an endpoint like https://adfs.school.edu/adfs/ls/?wa=wsignout1.0. Would I need to create a handler or just provide my existing IDP logout URL?
Any help, experiences, or thoughts would be appreciated
-Chris
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190123/76961968/attachment.html>
More information about the users
mailing list