<div dir="ltr">When it didn&#39;t work at first, I assumed it was because they didn&#39;t have any assertion consumers in their metadata. Then they put some in, but they are pointing every one to the same thing:<div><br></div>
<div><div>                                                &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>&quot; index=&quot;1&quot;/&gt;</div>
<div>                                                &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign&quot; Location=&quot;<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>&quot; index=&quot;2&quot;/&gt;</div>
<div>                                                &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:1.0:profiles:browser-post&quot; Location=&quot;<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>&quot; index=&quot;3&quot;/&gt;</div>
<div>                                                &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; Location=&quot;<a href="https://testing3.hiretouch.com/admin/saml/consume/">https://testing3.hiretouch.com/admin/saml/consume/</a>&quot; index=&quot;4&quot;/&gt;</div>
</div><div><br></div><div>Maybe this is some sort of super bit of code that is the all-weather tire of assertion consumers, but...</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, Aug 20, 2013 at 12:30 PM, Ian Rifkin <span dir="ltr">&lt;<a href="mailto:irifkin@brandeis.edu" target="_blank">irifkin@brandeis.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Hi Scott,<br><br><br><div><div class="gmail_extra"><div class="gmail_quote"><div class="im"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div>
No. You need metadata for them, which you should supply in a file with<br></div>
metadata for all such unmanaged partners, and then just load it.</blockquote><div><br></div></div><div>Can you explain this more? Do you mean Karla should insist the vendor supply metadata or are you talking about <i>creating</i> metadata; If the latter, is there any information on how to do that / what should that look like? <br>

</div><div class="im"><div>  <br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>
That&#39;s not a valid endpoint at the IdP. That you&#39;ll have to take up with<br></div>
them, it&#39;s not up to your IdP how the requests are generated.<br></blockquote><div><br></div></div><div>They could be going to the wrong IdP URL for the protocol (especially if they&#39;re not getting it from your metadata), right?<br>

</div><div> <br></div><div>Regards,<br>Ian<br></div></div></div></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div style="margin-left:40px">
Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div>
</div>