<div>We're using HTTP-Post, so the latter. </div><div><br></div><div>Though I'd characterize it more that we "accept the risk of..." than that we "not worry about the lack of..." :) </div><div><br>
</div><div>--- Eric</div><div><div><br><div class="gmail_quote">On Mon, Jun 11, 2012 at 11:19 AM, Chad La Joie <span dir="ltr"><<a href="mailto:lajoie@itumi.biz" target="_blank">lajoie@itumi.biz</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Eric, did you move to an attribute query model as well or did you just<br>
not worry about the lack of end-to-end confidentiality?<br>
<div class="HOEnZb"><div class="h5"><br>
On Mon, Jun 11, 2012 at 2:16 PM, Eric Goodman <<a href="mailto:ericg@ucsc.edu">ericg@ucsc.edu</a>> wrote:<br>
> This is not really answering your direct question, but tangentially we had<br>
> this issue with a different vendor.<br>
><br>
> Our solution was to verify that the vendor's SAML client still verified the<br>
> message signature. Knowing the signature was checked, that ssl was being<br>
> used on all of the SAML transactions, and that the data being sent was<br>
> relatively benign (ePPN in this case) we got the okay to integrate without<br>
> encrypted assertions.<br>
><br>
> --- Eric<br>
><br>
><br>
> On Mon, Jun 11, 2012 at 10:33 AM, Keith Hazelton <<a href="mailto:hazelton@doit.wisc.edu">hazelton@doit.wisc.edu</a>><br>
> wrote:<br>
>><br>
>> -----BEGIN PGP SIGNED MESSAGE-----<br>
>> Hash: SHA1<br>
>><br>
>> Warren,<br>
>><br>
>> So that would leads me to ask Michael Chale--are you dropping Salesforce?<br>
>> If not, how are you addressing the conflict about encrypted vs.<br>
>> unencrypted?<br>
>><br>
>> --Keith<br>
>> ________________<br>
>> On Jun 11, 2012, at 13:23:55, Curry, Warren wrote:<br>
>><br>
>> > Andrew,<br>
>> ><br>
>> > I guess this response from Mike Chale at UF - College of Business was<br>
>> > bounced back to him I am forwarding on to the list.. We had issue due to<br>
>> > required encryption at UF.<br>
>> > Warren<br>
>> > ==================================.<br>
>> ><br>
>> > Good afternoon, Andrew<br>
>> ><br>
>> ><br>
>> > We tried to use Shibboleth as an IdP but ran into a few stumbling<br>
>> > blocks, one of which was a show-stopper - Salesforce cannot handle encrypted<br>
>> > responses from the IdP and our university's current policy is to only<br>
>> > provide encrypted responses.<br>
>> ><br>
>> > If you would like to discuss any further details I would be happy to<br>
>> > help you out.<br>
>> ><br>
>> ><br>
>> > Michael Chale<br>
>> > Solutions Engineer<br>
>> > Technology Solutions<br>
>> ><br>
>> > -----Original Message-----<br>
>> > From: <a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [mailto:<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>]<br>
>> > On Behalf Of Andrew Morgan<br>
>> > Sent: Monday, June 11, 2012 12:52 PM<br>
>> > To: Shib Users<br>
>> > Subject: Re: Salesforce with Shibboleth IdP<br>
>> ><br>
>> > On Fri, 8 Jun 2012, Peter Schober wrote:<br>
>> ><br>
>> >> * Andrew Morgan <<a href="mailto:morgan@orst.edu">morgan@orst.edu</a>> [2012-06-07 18:42]:<br>
>> >>> Login Error<br>
>> >>> Your login attempt using single sign-on with an identity provider<br>
>> >>> certificate has failed. Please contact your <a href="http://salesforce.com" target="_blank">salesforce.com</a><br>
>> >>> administrator<br>
>> >>> for more information.<br>
>> >><br>
>> >> If all else fails you could try just that?<br>
>> >> -peter<br>
>> ><br>
>> > Unfortunately, my co-worker is the administrator and we are both trying<br>
>> > to understand what is going wrong! :)<br>
>> ><br>
>> > We have tried using Salesforce's SAML assertion validator, but that<br>
>> > doesn't raise any errors. I was hoping someone might have experience with<br>
>> > Salesforce, or at least have a working Shibboleth-Salesforce setup that I<br>
>> > could compare against.<br>
>> ><br>
>> > Thanks,<br>
>> > Andy<br>
>> > --<br>
>> > To unsubscribe from this list send an email to<br>
>> > <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
>> > --<br>
>> > To unsubscribe from this list send an email to<br>
>> > <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
>><br>
>> -----BEGIN PGP SIGNATURE-----<br>
>> Version: GnuPG/MacGPG2 v2.0.18 (Darwin)<br>
>> Comment: GPGTools - <a href="http://gpgtools.org" target="_blank">http://gpgtools.org</a><br>
>><br>
>> iQEcBAEBAgAGBQJP1ivXAAoJEPXbVHOlscTvm3MIAMCMEtbX82PVB2XKce1qK3j8<br>
>> zRK3q9Hz/9BfFWDScq5sMPFrmMicmhZiq59D+RCAshDOYmT/QpZ+81ciggCRLrlO<br>
>> cN8UfpUhQ5cZ4YYAXCrlsI+GY7k3zksIJpPIwDGBnA6mhlHfd0ed91HeY/mIUNnE<br>
>> C6zrP9lXiRDrWRWuwXJyYV8lEAUc3YHDzOColZQwZp7PIHZkLeij90lXDC5axrNr<br>
>> +LeFPD/YQd3WNJ3dJ9RjDJTuS6wnRfQT3UpwGxuXM+bKNBuS2AS3uHfU9zTehQd4<br>
>> 6vXEbkVLhivFjxZPwO2+3qSXBHq7xhi0PrNu1mWixesUPXNyMOQoSvuO7jRNqGc=<br>
>> =3tCg<br>
>> -----END PGP SIGNATURE-----<br>
>> --<br>
>> To unsubscribe from this list send an email to<br>
>> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
><br>
><br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
--<br>
</div></div><span class="HOEnZb"><font color="#888888">Chad La Joie<br>
<a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
trusted identities, delivered<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div></div>