<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>From the IDp:</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><br></span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; background-color: transparent; font-style: normal;"><span><span style="color: rgb(31, 73, 125); font-family: Calibri, sans-serif; font-size: 14.857142448425293px;">Hi Mike, we don’t actually use OIF for Learn. The Learn product has its own SAML solution, unrelated to OIF, and it’s only IDP-initiated.</span><br></span></div><div><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial">
 <hr size="1">  <b><span style="font-weight:bold;">From:</span></b> Mike Flynn &lt;shibbolethlynda@yahoo.com&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Thursday, February 7, 2013 10:01 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: IdP initiated SSO<br> </font> </div> <br>
<div id="yiv570482358"><div><div style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255); font-family: arial, helvetica, sans-serif; font-size: 12pt;"><div><span>It's Oracle corporation doing this... &nbsp;I will ask about the version. &nbsp;There is no relaystate in the assertion.</span></div><div><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1">  <b><span style="font-weight:bold;">From:</span></b> Marc Boorshtein &lt;mboorshtein@gmail.com&gt;<br> <b><span style="font-weight:bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight:bold;">Sent:</span></b> Thursday, February 7, 2013 9:58 AM<br> <b><span style="font-weight:bold;">Subject:</span></b> Re: IdP initiated SSO<br> </font> </div> <br>
What version of OIF are they using?&nbsp; I've done several OIF deployments<br>and I've never heard of an OIF server that can't do SP initiated when<br>they're the IdP.Is there a&nbsp; RelayState parameter in the post?<br><br>Marc<br><br>On Thu, Feb 7, 2013 at 12:47 PM, Mike Flynn &lt;<a rel="nofollow" ymailto="mailto:shibbolethlynda@yahoo.com" target="_blank" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br>&gt; I have a private fed trying to integrate to my Shib system.&nbsp; They are<br>&gt; running Oracle as the IdP and claim they cannot support SP initiated SSO.<br>&gt; All of the Idps that I integrate with all use SP initiated.&nbsp; I assume that<br>&gt; all they should need to do is POST an assertion to my endpoint here:<br>&gt;<br>&gt;&nbsp; &nbsp;  &lt;md:AssertionConsumerService<br>&gt; Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br>&gt; Location="http://shib.lynda.com/Shibboleth.sso/SAML2/POST"
 index="1"/&gt;<br>&gt;<br>&gt;
 They do that and get a 500 error on my servers and my logs show nothing.<br>&gt; The assertion they sent is this:<br>&gt;<br>&gt; &lt;samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<br>&gt; Destination="<a rel="nofollow" target="_blank" href="https://shib.lynda.com/Shibboleth.sso/SAML2/POST">https://shib.lynda.com/Shibboleth.sso/SAML2/POST</a>"<br>&gt; ID="uuid-DFB29937-C47F-4DD0-81EC-FF6579E8AC45" InResponseTo=""<br>&gt; IssueInstant="2013-02-07T17:05:41Z"Version="2.0"&gt;<br>&gt; &lt;Signature xmlns="http://www.w3.org/2000/09/xmldsig#"&gt;<br>&gt; &lt;SignedInfo&gt;<br>&gt; &lt;CanonicalizationMethod<br>&gt; Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/&gt;<br>&gt; &lt;SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/&gt;<br>&gt; &lt;Reference URI="#uuid-DFB29937-C47F-4DD0-81EC-FF6579E8AC45"&gt;<br>&gt; &lt;Transforms&gt;<br>&gt; &lt;Transform<br>&gt;
 Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/&gt;<br>&gt; &lt;Transform Algorithm="<a rel="nofollow" target="_blank" href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/&gt;<br>&gt; &lt;/Transforms&gt;<br>&gt; &lt;DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/&gt;<br>&gt; &lt;DigestValue&gt;C1fVRAnlLEWmsWgb4wKTpEEh84s=&lt;/DigestValue&gt;<br>&gt; &lt;/Reference&gt;<br>&gt; &lt;/SignedInfo&gt;<br>&gt; &lt;SignatureValue&gt;<br>&gt; NRfFI3Aj4B8Erl2UFFToEyHhd3CCOXKhklIALutt+3MzuZR5H33uU2G4DpQCGlpHv+uTe2ejwiz+CUbP1CcsP0+U4KXMevp+60XS7HDW240fayX7sNpvipdW4ZCkTC387VNDPk3G2H6dNpkiosvkfLQc1aBQfjADgh/NWcBRvf/79ht2TSMm/ccl2VL8HngRBEkRRz146uW4XqLuzWWlWctv3GF//I6kqumLBuirUS9E39YxUopiPgqU5zpBp1vZWPiVUi5sYQ9nYZMz+ZfxW9trd1rcVPudsOaQzSHHiLz7FkH6KVywuzRC18KzaHQW0ljhVPbm3oZxNW8JyNrcqg==<br>&gt; &lt;/SignatureValue&gt;<br>&gt; &lt;/Signature&gt;<br>&gt; &lt;samlp:Status&gt;<br>&gt;
 &lt;samlp:StatusCode
 Value="urn:oasis:names:tc:SAML:2.0:status:Success"/&gt;<br>&gt; &lt;/samlp:Status&gt;<br>&gt; &lt;saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"<br>&gt; ID="uuid-1323F186-A065-4588-B5C4-37B12E3BEC95"<br>&gt; IssueInstant="2013-02-07T17:05:41Z" Version="2.0"&gt;<br>&gt; &lt;saml:Issuer&gt;<a rel="nofollow" target="_blank" href="http://sapient.learn.com/">http://sapient.learn.com</a>&lt;/saml:Issuer&gt;<br>&gt; &lt;saml:Subject&gt;<br>&gt; &lt;saml:NameID&gt;LEARNSUPPORT&lt;/saml:NameID&gt;<br>&gt; &lt;/saml:Subject&gt;<br>&gt; &lt;saml:Conditions NotBefore="2013-02-07T17:04:41Z"<br>&gt; NotOnOrAfter="2013-02-07T17:10:41Z"&gt;<br>&gt; &lt;saml:AudienceRestriction/&gt;<br>&gt; &lt;/saml:Conditions&gt;<br>&gt; &lt;saml:AuthnStatement AuthnInstant="2013-02-07T17:05:41Z"<br>&gt; SessionNotOnOrAfter=""&gt;<br>&gt; &lt;saml:AuthnContext&gt;<br>&gt; &lt;saml:AuthnContextClassRef&gt;<br>&gt;
 urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport<br>&gt; &lt;/saml:AuthnContextClassRef&gt;<br>&gt; &lt;/saml:AuthnContext&gt;<br>&gt; &lt;/saml:AuthnStatement&gt;<br>&gt; &lt;saml:AttributeStatement&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" FriendlyName="eppn"&gt;<br>&gt; &lt;saml:AttributeValue&gt;LEARNSUPPORT&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:2.5.4.3" FriendlyName="uid"&gt;<br>&gt; &lt;saml:AttributeValue&gt;LEARNSUPPORT&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:2.5.4.4" FriendlyName="sn"&gt;<br>&gt; &lt;saml:AttributeValue&gt;Support&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:2.5.4.7" FriendlyName="l"&gt;<br>&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:2.5.4.42"
 FriendlyName="givenName"&gt;<br>&gt; &lt;saml:AttributeValue&gt;Learn&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:0.9.2342.19200300.100.1.3"<br>&gt; FriendlyName="mail"&gt;<br>&gt; &lt;saml:AttributeValue&gt;<a rel="nofollow" ymailto="mailto:CJohnson@Taleo.Com" target="_blank" href="mailto:CJohnson@Taleo.Com">CJohnson@Taleo.Com</a>&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:2.5.4.101" FriendlyName="C"&gt;<br>&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:2.5.4.102" FriendlyName="UO"&gt;<br>&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name="urn:oid:2.5.4.103" FriendlyName="Department"&gt;<br>&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;/saml:AttributeStatement&gt;<br>&gt; &lt;/saml:Assertion&gt;<br>&gt;
 &lt;/samlp:Response&gt;<br>&gt;<br>&gt; Are my assumptions correct regarding POST to my endpoint as detailed above?<br>&gt; Can anyone see an issue regarding the data in the assertion above?&nbsp; They<br>&gt; asked about RelayState but that is only valid for SP initiated, correct?<br>&gt;<br>&gt; --<br>&gt; To unsubscribe from this list send an email to<br>&gt; <a rel="nofollow" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>--<br>To unsubscribe from this list send an email to <a rel="nofollow" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br> </div> </div>  </div></div></div><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net"
 href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br> </div> </div>  </div></body></html>