PingOne SSO cloud integrations
Schwendner, Joanne
joanne_schwendner at brown.edu
Tue Jan 28 12:00:42 EST 2020
I am wondering if anyone else on this list has done SAML integrations with
users of "PingOne SSO for SaaS Apps" -- PingFederate's cloud-based,
multi-tenant product.
Recently we have had several different vendors present us with the same
metadata that they generated from this product -- the VERY SAME for all
vendors. Apparently the SP metadata they get when they set up an
integration uses the very same ACS endpoints and logout endpoints, and the
very same signing/encryption cert. A couple even had the same Entity ID.
(I turned those back.)
The most customization this product seems capable of is generating a unique
Entity ID which is a long GUID-looking string. I was told that the SP cert
cannot be changed; that is what the product uses. And the generic PingOne
endpoints are also correct. If I understand it correctly, we're expected
to return our assertion to the same PingOne endpoint for all of these
vendors, and PingOne sorts them out using that Entity ID, and directs them
to the correct tenant.
I'd be interested in comments about this.
Joanne
---
Joanne Schwendner
Senior Developer - Web, Integration, & Identity Services
Brown University
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200128/566f8e9e/attachment.html>
More information about the users
mailing list