<span style="font-family: Arial;">Yep that sounds like the OIF GUI &lt;shudder&gt;<br>I can take another look at configuration tomorrow AM.<br>I think I covered where we got tripped up though sign vs unsigned, NameId / format, and backing dir. were the main ones.<br> <br>And for the record our IdP is Shibboleth ;-)<br><br><br>sent from mobile<br><br>----- Reply message -----<br>From: &quot;lalithj&quot; &lt;j_lalith@hotmail.com&gt;<br>To: &lt;users@shibboleth.net&gt;<br>Subject: Shibboleth IdP integration with Oracle 11g Identity Federation<br>Date: Wed, Mar 27, 2013 9:40 PM<br><br></span><br>Thanks Scott,<br><br>I did further reading on OIF meaning of these fields, please find below,<br><br>Primarily provider ID and SSO Service URL are mandotory<br><br>SSO Service URL is not mandotory, that is the one gives this bad certificate<br>error etc.<br><br><br><br><br><br><br><br>Name<br> This is the provider name.<br> <br>Description<br> This is a brief description of the provider. (Optional).<br> <br>Protocol<br> This is the provider protocol (SAML 1.1, SAML 2.0 and so on).<br> <br>Service Details<br> This drop-down enables you to choose whether to enter service details<br>manually or load from metadata.<br> <br>Metadata File<br> This field appears if loading metadata from a file. Click Browse to select<br>a file to use.<br> <br>provider ID<br> This is the issuer ID of the provider.<br> <br>Succinct ID<br> This is the succinct ID of the provider. This element is required if using<br>the artifact profile.<br> <br>SSO Service URL<br> This is the URL address to which SSO requests are sent.<br> <br>SOAP Service URL<br> This is the URL address to which a SOAP service request is sent. This<br>element is required if using artifact profile.<br> <br>Logout Request Service URL<br> This is the URL address to which a logout request is sent by the provider.<br>This element is required if using the logout feature.<br> <br>Logout Response Service URL<br> This is the URL address to which a logout response is sent. This element is<br>required if using the logout feature.<br> <br>Signing Certificate<br> This is the signing certificate used by the provider. You can specify it in<br>pem and der formats.<br> <br>User Identity Store<br> This is the identity store against which a user is authenticated. If none<br>is selected, the default identity store is used.<br> <br>User Search Base DN<br> This is the base search DN used when looking up user records. (Optional. If<br>omitted, the default user search base DN configured for the selected user<br>identity store is used.)<br> <br><br><br><br><br><br><br><br><br><br>--<br>View this message in context: http://shibboleth.1660669.n2.nabble.com/Shibboleth-IdP-integration-with-Oracle-11g-Identity-Federation-tp7585604p7585721.html<br>Sent from the Shibboleth - Users mailing list archive at Nabble.com.<br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>