<p>It&#39;s been a while so let me dig it up. I&#39;ll send it directly to you. </p>
<p>Marc</p>
<div class="gmail_quote">On Feb 7, 2013 2:20 PM, &quot;Mike Flynn&quot; &lt;<a href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div><div style="font-size:12pt;font-family:arial,helvetica,sans-serif"><div><span>That would be awesome, Marc.</span></div><div><br></div>  <div style="font-family:arial,helvetica,sans-serif;font-size:12pt"> <div style="font-family:&#39;times new roman&#39;,&#39;new york&#39;,times,serif;font-size:12pt">
 <div dir="ltr"> <font face="Arial"> <hr size="1">  <b><span style="font-weight:bold">From:</span></b> Marc Boorshtein &lt;<a href="mailto:mboorshtein@gmail.com" target="_blank">mboorshtein@gmail.com</a>&gt;<br> <b><span style="font-weight:bold">To:</span></b> Shib Users &lt;<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>&gt; <br>
 <b><span style="font-weight:bold">Sent:</span></b> Thursday, February 7, 2013 11:19 AM<br> <b><span style="font-weight:bold">Subject:</span></b> Re: IdP initiated SSO<br> </font> </div> <br>
<div><div>Ok. Older versions of oif had a bug that would cause .net based signature validators to choke and vice versa.  Thought it might be related.</div>
<div>I use to have an opensaml based response validator. If you&#39;d like I can try nd find it and send it to you. </div>
<div>Marc</div>
<div>On Feb 7, 2013 1:34 PM, &quot;Mike Flynn&quot; &lt;<a rel="nofollow" href="mailto:shibbolethlynda@yahoo.com" target="_blank">shibbolethlynda@yahoo.com</a>&gt; wrote:<br><blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div><div style="font-size:12pt;font-family:arial,helvetica,sans-serif"><div><span>From the IDp:</span></div><div style="font-style:normal;font-size:16px;background-color:transparent;font-family:arial,helvetica,sans-serif">

<span><br></span></div><div style="font-style:normal;font-size:16px;background-color:transparent;font-family:arial,helvetica,sans-serif"><span><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.857142448425293px">Hi Mike, we don’t actually use OIF for Learn. The Learn product has its own SAML solution, unrelated to OIF, and it’s only IDP-initiated.</span><br>

</span></div><div><br></div>  <div style="font-family:arial,helvetica,sans-serif;font-size:12pt"> <div style="font-size:12pt"> <div dir="ltr"> <font face="Arial">
 <hr size="1">  <b><span style="font-weight:bold">From:</span></b> Mike Flynn &lt;<a rel="nofollow" href="mailto:shibbolethlynda@yahoo.com" target="_blank">shibbolethlynda@yahoo.com</a>&gt;<br> <b><span style="font-weight:bold">To:</span></b> Shib Users &lt;<a rel="nofollow" href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>&gt; <br>

 <b><span style="font-weight:bold">Sent:</span></b> Thursday, February 7, 2013 10:01 AM<br> <b><span style="font-weight:bold">Subject:</span></b> Re: IdP initiated SSO<br> </font> </div> <br>
<div><div><div style="font-size:12pt;font-family:arial,helvetica,sans-serif"><div><span>It&#39;s Oracle corporation doing this...  I will ask about the version.  There is no relaystate in the assertion.</span></div><div>

<br></div>  <div style="font-family:arial,helvetica,sans-serif;font-size:12pt"> <div style="font-size:12pt"> <div dir="ltr"> <font face="Arial"> <hr size="1">
  <b><span style="font-weight:bold">From:</span></b> Marc Boorshtein &lt;<a rel="nofollow" href="mailto:mboorshtein@gmail.com" target="_blank">mboorshtein@gmail.com</a>&gt;<br> <b><span style="font-weight:bold">To:</span></b> Shib Users &lt;<a rel="nofollow" href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>&gt; <br>

 <b><span style="font-weight:bold">Sent:</span></b> Thursday, February 7, 2013 9:58 AM<br> <b><span style="font-weight:bold">Subject:</span></b> Re: IdP initiated SSO<br> </font> </div> <br>
What version of OIF are they using?  I&#39;ve done several OIF deployments<br>and I&#39;ve never heard of an OIF server that can&#39;t do SP initiated when<br>they&#39;re the IdP.Is there a  RelayState parameter in the post?<br>

<br>Marc<br><br>On Thu, Feb 7, 2013 at 12:47 PM, Mike Flynn &lt;<a rel="nofollow" href="mailto:shibbolethlynda@yahoo.com" target="_blank">shibbolethlynda@yahoo.com</a>&gt; wrote:<br>&gt; I have a private fed trying to integrate to my Shib system.  They are<br>

&gt; running Oracle as the IdP and claim they cannot support SP initiated SSO.<br>&gt; All of the Idps that I integrate with all use SP initiated.  I assume that<br>&gt; all they should need to do is POST an assertion to my endpoint here:<br>

&gt;<br>&gt;     &lt;md:AssertionConsumerService<br>&gt; Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;<br>&gt; Location=&quot;<a href="http://shib.lynda.com/Shibboleth.sso/SAML2/POST" target="_blank">http://shib.lynda.com/Shibboleth.sso/SAML2/POST</a>&quot;
 index=&quot;1&quot;/&gt;<br>&gt;<br>&gt;
 They do that and get a 500 error on my servers and my logs show nothing.<br>&gt; The assertion they sent is this:<br>&gt;<br>&gt; &lt;samlp:Response xmlns:samlp=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;<br>&gt; Destination=&quot;<a rel="nofollow" href="https://shib.lynda.com/Shibboleth.sso/SAML2/POST" target="_blank">https://shib.lynda.com/Shibboleth.sso/SAML2/POST</a>&quot;<br>

&gt; ID=&quot;uuid-DFB29937-C47F-4DD0-81EC-FF6579E8AC45&quot; InResponseTo=&quot;&quot;<br>&gt; IssueInstant=&quot;2013-02-07T17:05:41Z&quot;Version=&quot;2.0&quot;&gt;<br>&gt; &lt;Signature xmlns=&quot;<a href="http://www.w3.org/2000/09/xmldsig#" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;<br>

&gt; &lt;SignedInfo&gt;<br>&gt; &lt;CanonicalizationMethod<br>&gt; Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;/&gt;<br>&gt; &lt;SignatureMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1" target="_blank">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>&quot;/&gt;<br>

&gt; &lt;Reference URI=&quot;#uuid-DFB29937-C47F-4DD0-81EC-FF6579E8AC45&quot;&gt;<br>&gt; &lt;Transforms&gt;<br>&gt; &lt;Transform<br>&gt;
 Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature" target="_blank">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>&quot;/&gt;<br>&gt; &lt;Transform Algorithm=&quot;<a rel="nofollow" href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;/&gt;<br>

&gt; &lt;/Transforms&gt;<br>&gt; &lt;DigestMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#sha1" target="_blank">http://www.w3.org/2000/09/xmldsig#sha1</a>&quot;/&gt;<br>&gt; &lt;DigestValue&gt;C1fVRAnlLEWmsWgb4wKTpEEh84s=&lt;/DigestValue&gt;<br>

&gt; &lt;/Reference&gt;<br>&gt; &lt;/SignedInfo&gt;<br>&gt; &lt;SignatureValue&gt;<br>&gt; NRfFI3Aj4B8Erl2UFFToEyHhd3CCOXKhklIALutt+3MzuZR5H33uU2G4DpQCGlpHv+uTe2ejwiz+CUbP1CcsP0+U4KXMevp+60XS7HDW240fayX7sNpvipdW4ZCkTC387VNDPk3G2H6dNpkiosvkfLQc1aBQfjADgh/NWcBRvf/79ht2TSMm/ccl2VL8HngRBEkRRz146uW4XqLuzWWlWctv3GF//I6kqumLBuirUS9E39YxUopiPgqU5zpBp1vZWPiVUi5sYQ9nYZMz+ZfxW9trd1rcVPudsOaQzSHHiLz7FkH6KVywuzRC18KzaHQW0ljhVPbm3oZxNW8JyNrcqg==<br>

&gt; &lt;/SignatureValue&gt;<br>&gt; &lt;/Signature&gt;<br>&gt; &lt;samlp:Status&gt;<br>&gt;
 &lt;samlp:StatusCode
 Value=&quot;urn:oasis:names:tc:SAML:2.0:status:Success&quot;/&gt;<br>&gt; &lt;/samlp:Status&gt;<br>&gt; &lt;saml:Assertion xmlns:saml=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot;<br>&gt; ID=&quot;uuid-1323F186-A065-4588-B5C4-37B12E3BEC95&quot;<br>

&gt; IssueInstant=&quot;2013-02-07T17:05:41Z&quot; Version=&quot;2.0&quot;&gt;<br>&gt; &lt;saml:Issuer&gt;<a rel="nofollow" href="http://sapient.learn.com/" target="_blank">http://sapient.learn.com</a>&lt;/saml:Issuer&gt;<br>

&gt; &lt;saml:Subject&gt;<br>&gt; &lt;saml:NameID&gt;LEARNSUPPORT&lt;/saml:NameID&gt;<br>&gt; &lt;/saml:Subject&gt;<br>&gt; &lt;saml:Conditions NotBefore=&quot;2013-02-07T17:04:41Z&quot;<br>&gt; NotOnOrAfter=&quot;2013-02-07T17:10:41Z&quot;&gt;<br>

&gt; &lt;saml:AudienceRestriction/&gt;<br>&gt; &lt;/saml:Conditions&gt;<br>&gt; &lt;saml:AuthnStatement AuthnInstant=&quot;2013-02-07T17:05:41Z&quot;<br>&gt; SessionNotOnOrAfter=&quot;&quot;&gt;<br>&gt; &lt;saml:AuthnContext&gt;<br>

&gt; &lt;saml:AuthnContextClassRef&gt;<br>&gt;
 urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport<br>&gt; &lt;/saml:AuthnContextClassRef&gt;<br>&gt; &lt;/saml:AuthnContext&gt;<br>&gt; &lt;/saml:AuthnStatement&gt;<br>&gt; &lt;saml:AttributeStatement&gt;<br>

&gt; &lt;saml:Attribute Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.6&quot; FriendlyName=&quot;eppn&quot;&gt;<br>&gt; &lt;saml:AttributeValue&gt;LEARNSUPPORT&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name=&quot;urn:oid:2.5.4.3&quot; FriendlyName=&quot;uid&quot;&gt;<br>

&gt; &lt;saml:AttributeValue&gt;LEARNSUPPORT&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name=&quot;urn:oid:2.5.4.4&quot; FriendlyName=&quot;sn&quot;&gt;<br>&gt; &lt;saml:AttributeValue&gt;Support&lt;/saml:AttributeValue&gt;<br>

&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name=&quot;urn:oid:2.5.4.7&quot; FriendlyName=&quot;l&quot;&gt;<br>&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name=&quot;urn:oid:2.5.4.42&quot;
 FriendlyName=&quot;givenName&quot;&gt;<br>&gt; &lt;saml:AttributeValue&gt;Learn&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name=&quot;urn:oid:0.9.2342.19200300.100.1.3&quot;<br>

&gt; FriendlyName=&quot;mail&quot;&gt;<br>&gt; &lt;saml:AttributeValue&gt;<a rel="nofollow" href="mailto:CJohnson@Taleo.Com" target="_blank">CJohnson@Taleo.Com</a>&lt;/saml:AttributeValue&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>

&gt; &lt;saml:Attribute Name=&quot;urn:oid:2.5.4.101&quot; FriendlyName=&quot;C&quot;&gt;<br>&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name=&quot;urn:oid:2.5.4.102&quot; FriendlyName=&quot;UO&quot;&gt;<br>

&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>&gt; &lt;saml:Attribute Name=&quot;urn:oid:2.5.4.103&quot; FriendlyName=&quot;Department&quot;&gt;<br>&gt; &lt;saml:AttributeValue/&gt;<br>&gt; &lt;/saml:Attribute&gt;<br>

&gt; &lt;/saml:AttributeStatement&gt;<br>&gt; &lt;/saml:Assertion&gt;<br>&gt;
 &lt;/samlp:Response&gt;<br>&gt;<br>&gt; Are my assumptions correct regarding POST to my endpoint as detailed above?<br>&gt; Can anyone see an issue regarding the data in the assertion above?  They<br>&gt; asked about RelayState but that is only valid for SP initiated, correct?<br>

&gt;<br>&gt; --<br>&gt; To unsubscribe from this list send an email to<br>&gt; <a rel="nofollow" href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>--<br>To unsubscribe from this list send an email to <a rel="nofollow" href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>

<br><br> </div> </div>  </div></div></div><br>--<br>To unsubscribe from this list send an email to <a rel="nofollow" href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
<br> </div> </div>
  </div></div><br>--<br>
To unsubscribe from this list send an email to <a rel="nofollow" href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br></blockquote></div>
</div><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br><br> </div> </div>  </div></div><br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div>