SAML Compliance / SSO Issues
TJ Peters
tpeters at leepfrog.com
Mon Apr 19 20:51:51 UTC 2021
Hello,
We are working on configuring our Shibboleth SP to work with a college
who is using Portal Guard as their IdP vendor. We currently have
one SP entityID. Tied to this, are many ACS urls, used by many
colleges and universities. However, this Portal Guard client says that
every ACS must be tied to a unique entityID, in their system.
Furthermore, this customer using Portal Guard is claiming that our SP
installation is not SAML compliant because we don't have a unique
entityID for every URL. They are pointing us to the Oasis standard,
2.2.1, that reads: "entityIDType is used as a unique identifier for
SAML entities. See also Section 8.3.6 of[SAMLCore]. An identifier of
this type MUST be unique across all entities that interact within a
givendeployment."
https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf
Our initial read of that paragraph is that they might be
mis-reading the SAML spec. Our entityID is unique. No other entity
shares it. But maybe we are misreading it and their reading is
correct. Can anybody confirm whether we are supposed to have
separate, unique entityIDs for every ACS?
Thanks!
More information about the users
mailing list