<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">For those who report successful integration of AWS with your Shibboleth IdP,<div><br></div><div>&gt; Are you configuring for unencrypted SAML response? (AWS SP metadata at&nbsp;<a href="https://signin.aws.amazon.com/static/saml-metadata.xml">https://signin.aws.amazon.com/static/saml-metadata.xml</a>&nbsp;includes a certificate for signing but no encryption cert)</div><div><br></div><div>&gt; Using “unsolicited” or “idp-initiated” response (<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUnsolicitedSSO">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUnsolicitedSSO</a>)&nbsp;</div><div>because AWS does not initiate the authN request?</div><div><br></div><div>&gt; something like:&nbsp;<font face="Monaco"><span style="text-decoration: underline; color: rgb(71, 135, 255);"><a href="https:/">https://</a><a href="http://idp.alaska.edu/"><span style="background-color: rgb(255, 251, 1);">idp.alaska.edu</span></a></span>/idp/profile/SAML2/Unsolicited/SSO?providerId=urn%3Aamazon%3Awebservices ?</font></div><div><br></div><div>David Bantz</div></body></html>