<div dir="ltr">Along the same lines, I tend to focus more on which profiles are supported, which identifiers, etc. Most every vendor "supports" SAML2 but they might require specific authentication mechanisms (ADFS) or have limitations such as only able to supply a user identifier in the assertion but not other attributes. <div>
<br></div><div style>Thanks</div><div style>Marc</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, May 28, 2013 at 5:26 PM, MikeWho <span dir="ltr"><<a href="mailto:who@me.com" target="_blank">who@me.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Thanks all for your advice!<br>
<br>
I guess the answer then is D) That's a bad question. There are better, more<br>
specific questions that you could ask that would reveal more about our<br>
interoperability. ;)<br>
<br>
FWIW, they use the Tivoli IdP, and we already have integrated with it for<br>
SSO & user provisioning. Now however we integrate with another service to<br>
pull additional data from their network, which is where this question came<br>
up.<br>
<br>
The saml2int profile is interesting, we're not strictly compliant with it as<br>
signed requests were a client requirement.<br>
<br>
(The funny thing about SAML integrations in my (limited!) experience, is how<br>
the real-world process matches the digital one, with both sides feeling each<br>
other out for their capabilities. "Do you know more about SAML than us, or<br>
do we need to walk you through it? etc.)<br>
<br>
Thanks all again!<br>
Mike.<br>
<br>
<br>
<br>
--<br>
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/SAML-2-0-Compliant-tp7587053p7587058.html" target="_blank">http://shibboleth.1660669.n2.nabble.com/SAML-2-0-Compliant-tp7587053p7587058.html</a><br>
<div class="im HOEnZb">Sent from the Shibboleth - Users mailing list archive at Nabble.com.<br>
</div><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>