SP handlerURL modification not working

Brent Goebel Brent.Goebel at du.edu
Tue Apr 6 23:32:44 UTC 2021


Thanks for the feedback Peter and Mark

I should note this is my first Shibboleth SP for me. I usually just do IDP setup.


So Without touching the handlerURL in the SP I am seeing successful authentication request from between the Shib SP and Shib IdP. In the IdP logs I can see the correct attributes passed to the SP.

But then in the website experience I get the IDP error page “web login service - unable to respond”.

So at this point the  vendor of the application said the consumer URL from the SP had to be that specific URL I shared. This doesn’t seem to be the case. It seems to be an issue between the SP not knowing where to redirect after authentication. If the SP and IdP are communicating correctly it is something between the app and SP right?

Thanks,

Brent

Get Outlook for iOS<https://aka.ms/o0ukef>
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Peter Schober <peter.schober at univie.ac.at>
Sent: Saturday, April 3, 2021 5:40:16 AM
To: users at shibboleth.net <users at shibboleth.net>
Subject: [EXTERNAL] Re: SP handlerURL modification not working

[External Email From]: users-bounces at shibboleth.net

* Brent Goebel <Brent.Goebel at du.edu> [2021-04-03 00:07]:
> Ellucian  is saying that the Consumer Assertion URL needs to be
> https://<hostname>/AppXtender/BdmSamlSso. So on their application
> they are looking for this URL format.

The only way this makes any sense is if they are acting as SAML SP and
will be decoding (and possibly decrypting) and processing the SAML
themselfs. Which is fine, it just doesn't have anything to do with
(and there'd be no need for) the Shibboleth SP software.

You can probably use their application (and whatever SAML 2.0 WebSSO
support that comes with it) with the Shibboleth IDP ("Identity
Provider") software, if you're running that. Maybe someone is
confusing those two.

> I already asked if they could modify their application code to take
> https://<hostname>/Shibboleth.sso/SAML2/POST and they there is no
> way to edit the expected Assertion URL on the application side. It
> has to match this AppXtender/BdmSamlSso.

Then I guess that's simply their SAML endpoint. Feed that to your SAML
IDP and forget about the Shibboleth SP.

-peter
--
For Consortium Member technical support, see https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!NCZxaNi9jForCP_SxBKJCA!GRw7uwXqSsaFhxQk27NGphqanaNhVYYz2W3JznuhMtWF3uCSQY5c-O7tNNXjQQeW1A$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210406/a15ddb9d/attachment.htm>


More information about the users mailing list