PingOne SSO cloud integrations
Schwendner, Joanne
joanne_schwendner at brown.edu
Tue Jan 28 13:55:53 EST 2020
I think the ones that sent metadata with the same EntityID didn't really
know how to configure their service in this cloud product.
For the one that came with a unique Entity ID, at least we have something
to go on to recognize the relying party. But I still can't say I am
comfortable with this.
Good idea to bring it up with PingOne support.
Joanne
On Tue, Jan 28, 2020 at 12:49 PM Peter Schober <peter.schober at univie.ac.at>
wrote:
> * Schwendner, Joanne <joanne_schwendner at brown.edu> [2020-01-28 18:01]:
> > Recently we have had several different vendors present us with the same
> > metadata that they generated from this product -- the VERY SAME for all
> > vendors. Apparently the SP metadata they get when they set up an
> > integration uses the very same ACS endpoints and logout endpoints, and
> the
> > very same signing/encryption cert. A couple even had the same Entity ID.
> > (I turned those back.)
>
> Well, with endpoints, keys and entityIDs being the same that just
> tells me in no uncertain terms it's just a single SP. Which would be
> fine as long as the policy requirements (attribute release, strong
> authentication, etc.) for everything behind that one SP were
> sufficiently similar -- and of course the SP doesn't run into trouble
> tracking just to what service I actually wanted to log in at any given
> point.
>
> I'm guessing the first condition may or may not be satisfied across
> the products having chosen this SAML outsourcing service. The latter
> condition -- the SP itself being fine with it -- already seems to have
> failed since you wrote:
>
> > PingOne sorts them out using that Entity ID, and directs them to the
> > correct tenant.
>
> So if they confuse themselfs by allowing duplicate entityIDs among
> their tenants, well, nothing good can come from that.
>
> -peter
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200128/e39bf24d/attachment.html>
More information about the users
mailing list