PingOne SSO cloud integrations
Nate Klingenstein
ndk at signet.id
Tue Jan 28 12:27:27 EST 2020
Joanne,
It has been possible until now. It's also possible that Ping has modified their product.
It seems very clear that the problem here is on the IdP side, as it should never use the same entityID(assuming it makes one for the SP or something -- it should consistently use just one for itself) or ACS points, to say nothing of the keypair. This will all cause problems regardless of the SP.
I think their support would be a more appropriate place to pose this question than here.
Take care,
Nate.
--------
Signet ®
The Art of Access ®
Nate Klingenstein | Principal
https://www.signet.id/
-----Original message-----
From: Schwendner, Joanne
Sent: Tuesday, January 28 2020, 10:01 am
To: users at shibboleth.net
Subject: PingOne SSO cloud integrations
I am wondering if anyone else on this list has done SAML integrations with users of "PingOne SSO for SaaS Apps" -- PingFederate's cloud-based, multi-tenant product.
Recently we have had several different vendors present us with the same metadata that they generated from this product -- the VERY SAME for all vendors. Apparently the SP metadata they get when they set up an integration uses the very same ACS endpoints and logout endpoints, and the very same signing/encryption cert. A couple even had the same Entity ID. (I turned those back.)
The most customization this product seems capable of is generating a unique Entity ID which is a long GUID-looking string. I was told that the SP cert cannot be changed; that is what the product uses. And the generic PingOne endpoints are also correct. If I understand it correctly, we're expected to return our assertion to the same PingOne endpoint for all of these vendors, and PingOne sorts them out using that Entity ID, and directs them to the correct tenant.
I'd be interested in comments about this.
Joanne
---
Joanne Schwendner
Senior Developer - Web, Integration, & Identity Services
Brown University
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200128/8326ff86/attachment.html>
More information about the users
mailing list