<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.hoenzb
        {mso-style-name:hoenzb;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Temporarily the college of business is assigning id directly for salesforce to a very few workers.&nbsp;&nbsp;&nbsp;&nbsp; This is not our preference.&nbsp;
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">If others are having issues with salesforce there is strength in numbers.&nbsp;&nbsp;&nbsp;
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Have have worked with many vendors with our IdP.&nbsp; Salesforce is first to refuse.&nbsp; However,&nbsp; I have not yet personally worked with the vendor to make it clear
 that we are not likely to change the encryption requirement between our IdP and the SP at salesforce.&nbsp;&nbsp;&nbsp;
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">We have 550 SP doing it&nbsp; one who is not wanting to..&nbsp; We will most likely hold the line on our requirement<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Warren
<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Eric Goodman<br>
<b>Sent:</b> Monday, June 11, 2012 2:37 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Salesforce with Shibboleth IdP<o:p></o:p></span></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">We're&nbsp;using HTTP-Post, so the latter.&nbsp;<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class="MsoNormal">Though I'd characterize it more that we &quot;accept the risk of...&quot; than that we &quot;not worry about the lack of...&quot;&nbsp;:)&nbsp;<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class="MsoNormal">--- Eric<o:p></o:p></p>
</div>
<div>
<div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">On Mon, Jun 11, 2012 at 11:19 AM, Chad La Joie &lt;<a href="mailto:lajoie@itumi.biz" target="_blank">lajoie@itumi.biz</a>&gt; wrote:<o:p></o:p></p>
<p class="MsoNormal">Eric, did you move to an attribute query model as well or did you just<br>
not worry about the lack of end-to-end confidentiality?<o:p></o:p></p>
<div>
<div>
<p class="MsoNormal"><br>
On Mon, Jun 11, 2012 at 2:16 PM, Eric Goodman &lt;<a href="mailto:ericg@ucsc.edu">ericg@ucsc.edu</a>&gt; wrote:<br>
&gt; This is not really answering your direct question, but tangentially we had<br>
&gt; this issue with a different vendor.<br>
&gt;<br>
&gt; Our solution was to verify that the vendor's SAML client still verified the<br>
&gt; message signature. Knowing the signature was checked, that ssl was being<br>
&gt; used on all of the SAML transactions, and that the data being sent was<br>
&gt; relatively benign (ePPN in this case) we got the okay to integrate without<br>
&gt; encrypted assertions.<br>
&gt;<br>
&gt; --- Eric<br>
&gt;<br>
&gt;<br>
&gt; On Mon, Jun 11, 2012 at 10:33 AM, Keith Hazelton &lt;<a href="mailto:hazelton@doit.wisc.edu">hazelton@doit.wisc.edu</a>&gt;<br>
&gt; wrote:<br>
&gt;&gt;<br>
&gt;&gt; -----BEGIN PGP SIGNED MESSAGE-----<br>
&gt;&gt; Hash: SHA1<br>
&gt;&gt;<br>
&gt;&gt; Warren,<br>
&gt;&gt;<br>
&gt;&gt; So that would leads me to ask Michael Chale--are you dropping Salesforce?<br>
&gt;&gt; &nbsp;If not, how are you addressing the conflict about encrypted vs.<br>
&gt;&gt; unencrypted?<br>
&gt;&gt;<br>
&gt;&gt; &nbsp; &nbsp; &nbsp; --Keith<br>
&gt;&gt; ________________<br>
&gt;&gt; On Jun 11, 2012, at 13:23:55, Curry, Warren wrote:<br>
&gt;&gt;<br>
&gt;&gt; &gt; Andrew,<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; I guess this response from Mike Chale at UF - College of Business was<br>
&gt;&gt; &gt; bounced back to him I am forwarding on to the list.. &nbsp;We had issue due to<br>
&gt;&gt; &gt; required encryption at UF.<br>
&gt;&gt; &gt; Warren<br>
&gt;&gt; &gt; ==================================.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Good afternoon, Andrew<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; We tried to use Shibboleth as an IdP but ran into a few stumbling<br>
&gt;&gt; &gt; blocks, one of which was a show-stopper - Salesforce cannot handle encrypted<br>
&gt;&gt; &gt; responses from the IdP and our university's current policy is to only<br>
&gt;&gt; &gt; provide encrypted responses.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; If you would like to discuss any further details I would be happy to<br>
&gt;&gt; &gt; help you out.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; &nbsp;Michael Chale<br>
&gt;&gt; &gt; &nbsp;Solutions Engineer<br>
&gt;&gt; &gt; &nbsp;Technology Solutions<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; -----Original Message-----<br>
&gt;&gt; &gt; From: <a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [mailto:<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>]<br>
&gt;&gt; &gt; On Behalf Of Andrew Morgan<br>
&gt;&gt; &gt; Sent: Monday, June 11, 2012 12:52 PM<br>
&gt;&gt; &gt; To: Shib Users<br>
&gt;&gt; &gt; Subject: Re: Salesforce with Shibboleth IdP<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; On Fri, 8 Jun 2012, Peter Schober wrote:<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt;&gt; * Andrew Morgan &lt;<a href="mailto:morgan@orst.edu">morgan@orst.edu</a>&gt; [2012-06-07 18:42]:<br>
&gt;&gt; &gt;&gt;&gt; &nbsp; Login Error<br>
&gt;&gt; &gt;&gt;&gt; &nbsp; Your login attempt using single sign-on with an identity provider<br>
&gt;&gt; &gt;&gt;&gt; &nbsp; certificate has failed. Please contact your <a href="http://salesforce.com" target="_blank">
salesforce.com</a><br>
&gt;&gt; &gt;&gt;&gt; administrator<br>
&gt;&gt; &gt;&gt;&gt; &nbsp; for more information.<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt; If all else fails you could try just that?<br>
&gt;&gt; &gt;&gt; -peter<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Unfortunately, my co-worker is the administrator and we are both trying<br>
&gt;&gt; &gt; to understand what is going wrong! &nbsp;:)<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; We have tried using Salesforce's SAML assertion validator, but that<br>
&gt;&gt; &gt; doesn't raise any errors. &nbsp;I was hoping someone might have experience with<br>
&gt;&gt; &gt; Salesforce, or at least have a working Shibboleth-Salesforce setup that I<br>
&gt;&gt; &gt; could compare against.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Thanks,<br>
&gt;&gt; &gt; &nbsp; &nbsp; &nbsp; Andy<br>
&gt;&gt; &gt; --<br>
&gt;&gt; &gt; To unsubscribe from this list send an email to<br>
&gt;&gt; &gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
&gt;&gt; &gt; --<br>
&gt;&gt; &gt; To unsubscribe from this list send an email to<br>
&gt;&gt; &gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
&gt;&gt;<br>
&gt;&gt; -----BEGIN PGP SIGNATURE-----<br>
&gt;&gt; Version: GnuPG/MacGPG2 v2.0.18 (Darwin)<br>
&gt;&gt; Comment: GPGTools - <a href="http://gpgtools.org" target="_blank">http://gpgtools.org</a><br>
&gt;&gt;<br>
&gt;&gt; iQEcBAEBAgAGBQJP1ivXAAoJEPXbVHOlscTvm3MIAMCMEtbX82PVB2XKce1qK3j8<br>
&gt;&gt; zRK3q9Hz/9BfFWDScq5sMPFrmMicmhZiq59D&#43;RCAshDOYmT/QpZ&#43;81ciggCRLrlO<br>
&gt;&gt; cN8UfpUhQ5cZ4YYAXCrlsI&#43;GY7k3zksIJpPIwDGBnA6mhlHfd0ed91HeY/mIUNnE<br>
&gt;&gt; C6zrP9lXiRDrWRWuwXJyYV8lEAUc3YHDzOColZQwZp7PIHZkLeij90lXDC5axrNr<br>
&gt;&gt; &#43;LeFPD/YQd3WNJ3dJ9RjDJTuS6wnRfQT3UpwGxuXM&#43;bKNBuS2AS3uHfU9zTehQd4<br>
&gt;&gt; 6vXEbkVLhivFjxZPwO2&#43;3qSXBHq7xhi0PrNu1mWixesUPXNyMOQoSvuO7jRNqGc=<br>
&gt;&gt; =3tCg<br>
&gt;&gt; -----END PGP SIGNATURE-----<br>
&gt;&gt; --<br>
&gt;&gt; To unsubscribe from this list send an email to<br>
&gt;&gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to<br>
&gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
--<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><span class="hoenzb"><span style="color:#888888">Chad La Joie</span></span><span style="color:#888888"><br>
<span class="hoenzb"><a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a></span><br>
<span class="hoenzb">trusted identities, delivered</span></span><o:p></o:p></p>
<div>
<div>
<p class="MsoNormal">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</div>
</div>
</body>
</html>