SAML Compliance / SSO Issues
Nate Klingenstein
ndk at signet.id
Mon Apr 19 20:58:33 UTC 2021
TJ,
It's perfectly legal to have multiple ACS URL's associated with a single entityID. If you want to spec back at them, lines 748-751 and 759-765 of:
https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf
The text they're pointing to is just meant to make sure that the entityID itself is unique and doesn't collide with any other.
Take care,
Nate.
--------
Signet, Inc.
The Art of Access ®
https://www.signet.id
-----Original message-----
From: TJ Peters
Sent: Monday, April 19 2021, 2:52 pm
To: users at shibboleth.net
Subject: SAML Compliance / SSO Issues
Hello,
We are working on configuring our Shibboleth SP to work with a college
who is using Portal Guard as their IdP vendor. We currently have
one SP entityID. Tied to this, are many ACS urls, used by many
colleges and universities. However, this Portal Guard client says that
every ACS must be tied to a unique entityID, in their system.
Furthermore, this customer using Portal Guard is claiming that our SP
installation is not SAML compliant because we don't have a unique
entityID for every URL. They are pointing us to the Oasis standard,
2.2.1, that reads: "entityIDType is used as a unique identifier for
SAML entities. See also Section 8.3.6 of[SAMLCore]. An identifier of
this type MUST be unique across all entities that interact within a
givendeployment."
https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf <https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf>
Our initial read of that paragraph is that they might be
mis-reading the SAML spec. Our entityID is unique. No other entity
shares it. But maybe we are misreading it and their reading is
correct. Can anybody confirm whether we are supposed to have
separate, unique entityIDs for every ACS?
Thanks!
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg <https://wiki.shibboleth.net/confluence/x/coFAAg>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net>
More information about the users
mailing list