Notice from Adobe about IdP SHA-1 certificates

Donald Lohr lohrda at jmu.edu
Thu Sep 3 16:46:50 UTC 2020


Right/wrong/in-different, our current Adobe/okta configuration in 
Shibboleth reference the following:

*saml-nameid.xml*

<bean parent="shibboleth.SAML2AttributeSourcedGenerator"
p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
        p:attributeSourceIds="#{ {'AdobeEmail'} }" >

*attribute-filter.xml*

<afp:AttributeRule attributeID="AdobeEmail">
        <afp:PermitValueRule xsi:type="basic:ANY" />
</afp:AttributeRule>

<afp:AttributeRule attributeID="AdobeFirstName">
        <afp:PermitValueRule xsi:type="basic:ANY" />
</afp:AttributeRule>

<afp:AttributeRule attributeID="AdobeLastName">
        <afp:PermitValueRule xsi:type="basic:ANY" />
</afp:AttributeRule>

Looking at the Adobe SAML configuration and the Adobe Admin tool 
documentation, I see no reference to what an attribute needs to be 
called or any mapping to what the IdP passes to Adobe.

What are others passing?

Thanks,
Don


On 7/21/20 2:28 PM, Lee Foltz wrote:
> Yesterday I followed these instructions from Abobe and had to Add new 
> IDP, which was just uploading our metadata again, then they provided a 
> link to download or use URL to use Adobe new SP metadata with SHA-256 
> certificate.
> https://helpx.adobe.com/enterprise/using/set-up-identity.html#migrateesaml 
> <https://urldefense.proofpoint.com/v2/url?u=https-3A__helpx.adobe.com_enterprise_using_set-2Dup-2Didentity.html-23migrateesaml&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=skrs6JyaDISVRDB8JrV7-2DX-Pa2t5d-tdQWiM1ixFU&e=>
>
> There is also a Test feature to test the new IDP setup with the new 
> Adobe SP metadata, you can also revert changes and roll back to other 
> IDP still configured (SHA-1) if your new setup doesn't work.
> We tested and had no issues with Federated Login on new setup with new 
> Adobe SP metadata.
>
> Hope this helps everyone.
>
> On Tue, Jul 21, 2020 at 9:43 AM Cantor, Scott <cantor.2 at osu.edu 
> <mailto:cantor.2 at osu.edu>> wrote:
>
>     On 7/21/20, 9:38 AM, "users on behalf of Peter Schober"
>     <users-bounces at shibboleth.net
>     <mailto:users-bounces at shibboleth.net> on behalf of
>     peter.schober at univie.ac.at <mailto:peter.schober at univie.ac.at>> wrote:
>
>     >    I'll definitively be keeping a reference to this thread handy
>     as I
>     >    feel I'll be needing it in the coming months.
>
>     This topic comes up nearly every ACAMP with no real solution, but
>     we need some kind of neutral venue for information sharing that we
>     can use to post this sort of knowledge that people will see.
>
>     -- Scott
>
>
>     -- 
>     For Consortium Member technical support, see
>     https://wiki.shibboleth.net/confluence/x/coFAAg
>     <https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=wxUvGKdwNA72T8Q0NE5MQ9WpPHF_fJwvBJk_aL5mmto&e=>
>     To unsubscribe from this list send an email to
>     users-unsubscribe at shibboleth.net
>     <mailto:users-unsubscribe at shibboleth.net>
>
>
>
> -- 
> Lee Foltz
> Oakland University - UTS
> Senior Identity and Access Management Engineer
> 248-370-2675
>

-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200903/98ceaeca/attachment.htm>


More information about the users mailing list