Notice from Adobe about IdP SHA-1 certificates
Donald Lohr
lohrda at jmu.edu
Thu Sep 3 16:46:50 UTC 2020
Right/wrong/in-different, our current Adobe/okta configuration in
Shibboleth reference the following:
*saml-nameid.xml*
<bean parent="shibboleth.SAML2AttributeSourcedGenerator"
p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
p:attributeSourceIds="#{ {'AdobeEmail'} }" >
*attribute-filter.xml*
<afp:AttributeRule attributeID="AdobeEmail">
<afp:PermitValueRule xsi:type="basic:ANY" />
</afp:AttributeRule>
<afp:AttributeRule attributeID="AdobeFirstName">
<afp:PermitValueRule xsi:type="basic:ANY" />
</afp:AttributeRule>
<afp:AttributeRule attributeID="AdobeLastName">
<afp:PermitValueRule xsi:type="basic:ANY" />
</afp:AttributeRule>
Looking at the Adobe SAML configuration and the Adobe Admin tool
documentation, I see no reference to what an attribute needs to be
called or any mapping to what the IdP passes to Adobe.
What are others passing?
Thanks,
Don
On 7/21/20 2:28 PM, Lee Foltz wrote:
> Yesterday I followed these instructions from Abobe and had to Add new
> IDP, which was just uploading our metadata again, then they provided a
> link to download or use URL to use Adobe new SP metadata with SHA-256
> certificate.
> https://helpx.adobe.com/enterprise/using/set-up-identity.html#migrateesaml
> <https://urldefense.proofpoint.com/v2/url?u=https-3A__helpx.adobe.com_enterprise_using_set-2Dup-2Didentity.html-23migrateesaml&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=skrs6JyaDISVRDB8JrV7-2DX-Pa2t5d-tdQWiM1ixFU&e=>
>
> There is also a Test feature to test the new IDP setup with the new
> Adobe SP metadata, you can also revert changes and roll back to other
> IDP still configured (SHA-1) if your new setup doesn't work.
> We tested and had no issues with Federated Login on new setup with new
> Adobe SP metadata.
>
> Hope this helps everyone.
>
> On Tue, Jul 21, 2020 at 9:43 AM Cantor, Scott <cantor.2 at osu.edu
> <mailto:cantor.2 at osu.edu>> wrote:
>
> On 7/21/20, 9:38 AM, "users on behalf of Peter Schober"
> <users-bounces at shibboleth.net
> <mailto:users-bounces at shibboleth.net> on behalf of
> peter.schober at univie.ac.at <mailto:peter.schober at univie.ac.at>> wrote:
>
> > I'll definitively be keeping a reference to this thread handy
> as I
> > feel I'll be needing it in the coming months.
>
> This topic comes up nearly every ACAMP with no real solution, but
> we need some kind of neutral venue for information sharing that we
> can use to post this sort of knowledge that people will see.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> <https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=wxUvGKdwNA72T8Q0NE5MQ9WpPHF_fJwvBJk_aL5mmto&e=>
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
> <mailto:users-unsubscribe at shibboleth.net>
>
>
>
> --
> Lee Foltz
> Oakland University - UTS
> Senior Identity and Access Management Engineer
> 248-370-2675
>
--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200903/98ceaeca/attachment.htm>
More information about the users
mailing list