Shibboleth SSO with Fortigate100F

Peter Schober peter.schober at univie.ac.at
Mon Sep 25 09:12:00 UTC 2023


Axel Philipp <Axel.Philipp at biophys.mpg.de> [2023-09-25 10:53 CEST]:
> set user-name "username"

And your IDP releases an attribute with "basic" name format (for
correctness; not that the SP implementation is likely to look at that)
named "username"?
What NameID Format does the IDP release? I'm guessing transient?

> We have tried the settings for the ACS- and SLS-Urls with a trailing
> '/' as well, but it didn't get us any further.

According to your previous post the SP complains about missing details
(NameID) within the SAML Assertion (though you said the "debug message
says something like" which is not good enough when debugging -- you
want the *exact* error message).
If any of the URLs were wrong you'd never even get that far, would
you? Of course the error message text could be wildly inaccurate /
misleading, I suppose.

Either way, you can trace where the SAML goes with e.g. the SAMLtracer
browser extension and verify that it matches what you've configured at
the SP.

-peter


More information about the users mailing list