<div dir="ltr">So, Scott, just to verify: when you say it isn&#39;t a valid endpoint at the IdP, do you mean their url/request (that I included earlier) is asking for something incorrectly, or something that the IdP doesn&#39;t understand, or is missing information? <div>
<br></div><div>Any or all of the above?</div><div><br></div><div>(sorry to bug you again)</div><div><br></div><div>Gratefully,</div><div>Karla</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, Aug 20, 2013 at 11:28 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">On 8/20/13 11:24 AM, &quot;Karla Borecky&quot; &lt;<a href="mailto:kborecky@smith.edu">kborecky@smith.edu</a>&gt; wrote:<br>

<br>
&gt;I am working with a vendor who has just given me these two urls: one is<br>
&gt;the &quot;service&quot; url, the other is the &quot;consume&quot; url - and said that<br>
&gt;previously, that&#39;s all they gave people and it would work. No metadata,<br>
&gt;so I believe I am correct in thinking I need<br>
&gt; to create a custom relying party section for them.<br>
<br>
</div>No. You need metadata for them, which you should supply in a file with<br>
metadata for all such unmanaged partners, and then just load it. You don&#39;t<br>
need other special rules.<br>
<div class="im"><br>
&gt;But using the SAML2SSOProfile doesn&#39;t seem to work. When I go to their<br>
&gt;test site, it just brings up our IdP&#39;s metadata. I assume that&#39;s because<br>
&gt;it doesn&#39;t know what to do with the rest of the URL, maybe? The resulting<br>
&gt;url looks like this:<br>
<br>
</div>That&#39;s not a valid endpoint at the IdP. That you&#39;ll have to take up with<br>
them, it&#39;s not up to your IdP how the requests are generated.<br>
<div class="im"><br>
&gt;I&#39;ve tried to figure out how to configure the relying party to work with<br>
&gt;a relaystate url, if that is what I should be doing, but the only<br>
&gt;references I could find had an RPID in their relaystate string - which<br>
&gt;they don&#39;t have.<br>
<br>
</div>None of that is relevant to the issue.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div style="margin-left:40px">Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div>
</div>