Education vendor SSO configuration requires separate IDP entityIDs for each SP!
Florian Lengyel
Florian.Lengyel at cuny.edu
Wed Dec 21 19:24:45 UTC 2022
Yes, that's my experience also with other vendors. Very straightforward.
This vendor-integrated with inCommon no less--wants a different entityID instead of a different attribute.
Florian
From: users <users-bounces at shibboleth.net> On Behalf Of Spencer Thomas via users
Sent: Wednesday, December 21, 2022 2:12 PM
To: Shib Users <users at shibboleth.net>
Cc: Spencer Thomas <Spencer.Thomas at ithaka.org>
Subject: Re: Education vendor SSO configuration requires separate IDP entityIDs for each SP!
***ATTENTION: This email came from an external source. Do not open attachments or click on links from unknown senders or unexpected emails.***
As a service provider, I can say that we have definitely engineered our SP to accommodate multiple institutions using the same EntityID. We obviously require a different attribute, most typically eduPersonEntitlement, to distinguish between those institutions.
--
Spencer Thomas
Technical Architect
ITHAKA<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.ithaka.org_&d=DwMF-g&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=w05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo&m=-7wSFiZs9UnpG7XVXPI0EGCbeoYQIN29WOA31jKt9xgS3Fhd6SWJIFZB_ws_tmVV&s=jyh0wc2KV4OmMAQNrb5IkPgEobjmWSD3qUpajhlXcO0&e=>
301 E. Liberty St, Suite 250, Ann Arbor, MI 48104
Email: Spencer.Thomas at ithaka.org<mailto:Spencer.Thomas at ithaka.org>
Voicemail: +1-734-887-7004
ithaka.org<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.ithaka.org_&d=DwMF-g&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=w05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo&m=-7wSFiZs9UnpG7XVXPI0EGCbeoYQIN29WOA31jKt9xgS3Fhd6SWJIFZB_ws_tmVV&s=jyh0wc2KV4OmMAQNrb5IkPgEobjmWSD3qUpajhlXcO0&e=>
[Image removed by sender. ITHAKA logo]
On 12/21/22, 1:32 PM, "users" <users-bounces at shibboleth.net> wrote:
Caution: This message did not originate from within ITHAKA's email system. Please use caution when opening attachments and following links within this message.
[cid:image001.gif at 01D91547.F7E806A0]
Hi,
I'm writing from the City University of New York. We're attempting to enable SAML2 SSO with
a vendor who would configure a service provider instance for each of our 26 campuses-except
for one problem that I have never encountered in my years of configuring Shibboleth.
Their system will not accept the same IDP entity ID for two or more SPs. We have one SP instance
configured in their system (and in ours as a relying party) with our IDP metadata (we're running IDP 4.0.1).
This integration works as expected. When they attempt to configure a new SP instance, their system
generates the error message, "Duplicate IDP Entity ID. Another IDP profile has the same Entity ID."
Am I correct that this constraint on IDP and SP entityIDs is nonstandard?
In case I have made an unwarranted assumption about their system, the SAML2 specification or both, is there
a way to generate separate metadata for the same IDP with different entityIDs? One of their customers
(another university) provided the vendor with IDP metadata of the form entityID=constantURL?variableID=theID.
The ACS etc endpoints in their metadata also contained the additional argument. I do not know if this customer stood
up separate IDPs.
I feel as though I ought to apologize for this.
Sincerely,
Florian
[cid:image002.png at 01D91547.F7E806A0]
Florian Lengyel, PhD
Identity and Access Management
CUNY CIS 395 Hudson Street, New York, NY 10014
Voicemail: (646) 664-2370 Cell: (917) 621-7845
Email: florian.lengyel at cuny.edu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20221221/92beaddc/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ~WRD0001.jpg
Type: image/jpeg
Size: 823 bytes
Desc: ~WRD0001.jpg
URL: <http://shibboleth.net/pipermail/users/attachments/20221221/92beaddc/attachment.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.gif
Type: image/gif
Size: 92 bytes
Desc: image001.gif
URL: <http://shibboleth.net/pipermail/users/attachments/20221221/92beaddc/attachment.gif>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.png
Type: image/png
Size: 3894 bytes
Desc: image002.png
URL: <http://shibboleth.net/pipermail/users/attachments/20221221/92beaddc/attachment.png>
More information about the users
mailing list