Access issue with some publisher platforms

Peter Schober peter.schober at univie.ac.at
Sat Feb 20 13:53:15 UTC 2021


* Francis Jayakanth via users <users at shibboleth.net> [2021-02-20 14:39]:
> HI, we are using Shibboleth IdP 4.0.1 along with Azure AD tenant

FTR, I don't know what that means or how the "Azure AD tenant" part is
relevant to your Shibboleth IDP federating with those publishers.

> The attributes released from the IdP are: eduPersonEntitlement, eduPersonScopedAffiliation, and eduPersonTargetedID.

Note that many publishers require some sort of set-up process to be
completed. Sometimes that includes configuring exactly what attribute
(and value/s) should be used by the platform for access control, in a
self-service interface accessible only to selected representatives
from the institution.

This will differ for each publisher (which doesn't scale, of course).
E.g. here are some resources for Springer:

https://support.springer.com/en/support/solutions/articles/6000079288-shibboleth-access-for-institutions
and
https://idp.springer.com/help/sso

> The Springer site, link.springer.com throws up an Application error with Issue reference number:
> 1a4582-SAMLmessagevalidationfailedduringSingleSign-On

You'd have to ask Springer Nature what their own error messages mean
in detail. I have not encountered this myself with them so I couldn't say.

If you don't have any contact details for the SP the SAML entity
serving link.springer.com is "https://fsso.springer.com" and REFEDS
MET has dozens of entries for that entity, most of which providing
contact details:
https://met.refeds.org/met/search_service/?entityid=https://fsso.springer.com
E.g. my own registration lists "onlineservice at springernature.com" both
for technical and support requests.

-peter


More information about the users mailing list