<div dir="ltr">When it didn't work at first, I assumed it was because they didn't have any assertion consumers in their metadata. Then they put some in, but they are pointing every one to the same thing:<div><br></div>
<div><div> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>" index="1"/></div>
<div> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>" index="2"/></div>
<div> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>" index="3"/></div>
<div> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>" index="4"/></div>
</div><div><br></div><div>Maybe this is some sort of super bit of code that is the all-weather tire of assertion consumers, but...</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, Aug 20, 2013 at 12:30 PM, Ian Rifkin <span dir="ltr"><<a href="mailto:irifkin@brandeis.edu" target="_blank">irifkin@brandeis.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Hi Scott,<br><br><br><div><div class="gmail_extra"><div class="gmail_quote"><div class="im"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div>
No. You need metadata for them, which you should supply in a file with<br></div>
metadata for all such unmanaged partners, and then just load it.</blockquote><div><br></div></div><div>Can you explain this more? Do you mean Karla should insist the vendor supply metadata or are you talking about <i>creating</i> metadata; If the latter, is there any information on how to do that / what should that look like? <br>
</div><div class="im"><div> <br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>
That's not a valid endpoint at the IdP. That you'll have to take up with<br></div>
them, it's not up to your IdP how the requests are generated.<br></blockquote><div><br></div></div><div>They could be going to the wrong IdP URL for the protocol (especially if they're not getting it from your metadata), right?<br>
</div><div> <br></div><div>Regards,<br>Ian<br></div></div></div></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div style="margin-left:40px">
Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div>
</div>