<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">FYI, for comment. &nbsp; --KeithH<br><div>_______<br><div>Begin forwarded message:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>From: </b></span><span style="font-family:'Helvetica'; font-size:medium;">Ryan Larscheidt &lt;<a href="mailto:larscheidt@doit.wisc.edu">larscheidt@doit.wisc.edu</a>&gt;<br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>Date: </b></span><span style="font-family:'Helvetica'; font-size:medium;">August 15, 2012 1:12:02 PM CDT<br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>To: </b></span><span style="font-family:'Helvetica'; font-size:medium;">Steve Devoti &lt;<a href="mailto:devoti@wisc.edu">devoti@wisc.edu</a>&gt;, Keith Hazelton &lt;<a href="mailto:hazelton@wisc.edu">hazelton@wisc.edu</a>&gt;<br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>Cc: </b></span><span style="font-family:'Helvetica'; font-size:medium;">Access Management Developers &lt;<a href="mailto:am-dev@lists.wisc.edu">am-dev@lists.wisc.edu</a>&gt;<br></span></div><div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px;"><span style="font-family:'Helvetica'; font-size:medium; color:rgba(0, 0, 0, 1);"><b>Subject: </b></span><span style="font-family:'Helvetica'; font-size:medium;"><b>Re: Working with an ADFS Proxy server.</b><br></span></div><br><div>In July, Microsoft announced that they natively support SAML2 and ECP, so there's no longer any reason to try to glue Shibboleth and ADFS together. &nbsp;<a href="http://technet.microsoft.com/en-us/library/jj205456.aspx">http://technet.microsoft.com/en-us/library/jj205456.aspx</a><br><br>Depending on what policy decisions are made, we'll (probably) either go full Microsoft (AD, ADFS, DirSync, etc), or we'll use SAML2 and ECP for authentication and provision accounts with FIM.<br><br>Thanks,<br>Ryan<br><br>On Aug 15, 2012, at 12:57 , Steve Devoti wrote:<br><br><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">From: Keith Hazelton [mailto:hazelton@wisc.edu] <br></blockquote><blockquote type="cite">Sent: Wednesday, August 15, 2012 12:45 PM<br></blockquote><blockquote type="cite">To: Steve Devoti; Joe Tarter<br></blockquote><blockquote type="cite">Subject: Fwd: Working with an ADFS Proxy server.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Possibly relevant to the Office 365 project if solutions involve MS ADFS. &nbsp;&nbsp;&nbsp;--keith<br></blockquote><blockquote type="cite">__________<br></blockquote><blockquote type="cite">Begin forwarded message:<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">From: "Cantor, Scott" &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt;<br></blockquote><blockquote type="cite">Date: August 15, 2012 12:38:20 PM CDT<br></blockquote><blockquote type="cite">To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br></blockquote><blockquote type="cite">Subject: Re: Working with an ADFS Proxy server.<br></blockquote><blockquote type="cite">Reply-To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">The problem is that the ADFS proxy (<a href="http://sso.a.example.com">sso.a.example.com</a>) requires the<br></blockquote><blockquote type="cite">"Destination" XML attribute be set to "<a href="http://adfs.a.example.com">adfs.a.example.com</a>".<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">That's a bug. The analagous scenario is a load balancer doing SSL<br></blockquote><blockquote type="cite">offloading. Even though the back end server is at a different physical<br></blockquote><blockquote type="cite">location, it must pretend to be the virtual location of the load balancer<br></blockquote><blockquote type="cite">when it performs such comparisons. People screw this up with the SP and<br></blockquote><blockquote type="cite">IdP all the time, because it's the web server's responsibility to do these<br></blockquote><blockquote type="cite">adjustments.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Note that IIS does not support those adjustments either, which is probably<br></blockquote><blockquote type="cite">relevant to an ADFS situation.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">If MS supports a proxied scenario but does not support virtualizing the<br></blockquote><blockquote type="cite">back end, you can't make it work.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">The ADFS administrators says that the HTTP POST/Redirect URLs need to<br></blockquote><blockquote type="cite">be set to <a href="http://sso.a.example.com">sso.a.example.com</a> while the "Destination" AuthnRequest<br></blockquote><blockquote type="cite">attribute must be set to "<a href="http://adfs.a.example.com">adfs.a.example.com</a>". How can I achieve this?<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">You can't. Well, you could change the code (or add plugins that duplicate<br></blockquote><blockquote type="cite">but tweak this value), but I'm ignoring that option.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">I could imagine some very ugly hacks such as an option to override the<br></blockquote><blockquote type="cite">Destination value based on some kind of mapping table, but that's not<br></blockquote><blockquote type="cite">implemented now.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">How have other people interoperated with ADFS proxies?<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">I would imagine they have not. A page to document things that don't work,<br></blockquote><blockquote type="cite">or how to work around issues is here:<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop">https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop</a><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">-- Scott<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">--<br></blockquote><blockquote type="cite">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote><blockquote type="cite"><br></blockquote><br></div></blockquote></div><br></body></html>