<div dir="ltr">Well, I did ask them to give me metadata, and they didn't really know how to generate it. I had to give them examples of what it should have. After it looked sort of OK, I configured everything for them the way I usually do - and used the aacli shell script to make sure it was giving them attributes etc. - but still it just displayed the IdP metadata when you went to the site.<div>
<br></div><div>Maybe I should just punt and tell them we want to do LDAP. They really don't seem to know at all how their process works under the hood, and I'm tired of guessing.</div></div><div class="gmail_extra">
<br><br><div class="gmail_quote">On Tue, Aug 20, 2013 at 11:28 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 8/20/13 11:24 AM, "Karla Borecky" <<a href="mailto:kborecky@smith.edu">kborecky@smith.edu</a>> wrote:<br>
<br>
>I am working with a vendor who has just given me these two urls: one is<br>
>the "service" url, the other is the "consume" url - and said that<br>
>previously, that's all they gave people and it would work. No metadata,<br>
>so I believe I am correct in thinking I need<br>
> to create a custom relying party section for them.<br>
<br>
</div>No. You need metadata for them, which you should supply in a file with<br>
metadata for all such unmanaged partners, and then just load it. You don't<br>
need other special rules.<br>
<div class="im"><br>
>But using the SAML2SSOProfile doesn't seem to work. When I go to their<br>
>test site, it just brings up our IdP's metadata. I assume that's because<br>
>it doesn't know what to do with the rest of the URL, maybe? The resulting<br>
>url looks like this:<br>
<br>
</div>That's not a valid endpoint at the IdP. That you'll have to take up with<br>
them, it's not up to your IdP how the requests are generated.<br>
<div class="im"><br>
>I've tried to figure out how to configure the relying party to work with<br>
>a relaystate url, if that is what I should be doing, but the only<br>
>references I could find had an RPID in their relaystate string - which<br>
>they don't have.<br>
<br>
</div>None of that is relevant to the issue.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div style="margin-left:40px">Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div>
</div>