Access issue with some publisher platforms
Robert Bradley
robert.bradley at it.ox.ac.uk
Tue Feb 23 15:19:36 UTC 2021
On 20/02/2021 13:38, Francis Jayakanth via users wrote:
> HI, we are using Shibboleth IdP 4.0.1 along with Azure AD tenant to
> facilitate federated access to subscribed online resources from the
> various publishers like Elsevier, ACS, Wiley etc. While the access is
> working fine on most of the publishers' platforms, we are having issues
> with a few platforms that include Springer Link, Springer Nature (for
> Nature branded journals), and Web of Science.
>
> The attributes released from the IdP are: eduPersonEntitlement,
> eduPersonScopedAffiliation, and eduPersonTargetedID.
>
> The Springer site, link.springer.com throws up an Application error with
> Issue reference number:
> 1a4582-SAMLmessagevalidationfailedduringSingleSign-On
>
> Can anyone help us to resolve the issue?
>
I'm not sure if it helps, but if you did the upgrade to IdP v4 at the
same time as the switch to using Azure AD and the IdP's SAML flow for
authentication, it's possible that it's actually objecting to the IdP
attempting to use GCM encryption. If that's the case, try setting:
idp.encryption.config=shibboleth.EncryptionConfiguration.CBC
in idp.properties and see if that helps.
--
Dr Robert Bradley
Identity and Access Management Team, IT Services, University of Oxford
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20210223/6ffbaeea/attachment.sig>
More information about the users
mailing list