<div dir="ltr"><div>Hi Scott,<br><br></div>Sorry for the confusions.<br><div class="gmail_extra">He told me in other thread that to apply Federated settings, I first have to make Authentication &quot;Managed&quot; and then apply Federation settings again. This worked.<br>
<br></div><div class="gmail_extra">Secondly, about the link FederationMetaDataUrl. I understand that it has nothing to do (for this scenario at least) after the discussion had with Rob. May be my understanding was wrong. I thought that SP needs a metadata to process the flow and vice versa. But here, only our IdP needs metadata file.<br>
<br></div><div class="gmail_extra">You are right that restarting the computer has to do nothing because Office365 is a separate entity and uncontrolled. I removed the ADFS role because after applying federation changes, it was overwriting the settings I was supplying. That is why I mentioned that I restarted the system. I was just trying to scope down the issue :-)<br>
<br></div><div class="gmail_extra">Sorry again for all the confusion. <br></div><div class="gmail_extra"><br><div class="gmail_quote">On 20 August 2014 14:48, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On 8/19/14, 10:14 PM, &quot;Farzan Qureshi&quot; &lt;<a href="mailto:fqureshi@rosmini.school.nz">fqureshi@rosmini.school.nz</a>&gt; wrote:<br>

&gt;<br>
&gt;Ok first thing first. I was working with ADFS to federate our domain with<br>
&gt;office365. However there were several issues related to it. We planned to<br>
&gt;move from it to Shibboleth. We have completely remove ADFS role from the<br>
&gt;system. We have also uninstalled Microsoft<br>
&gt; ADFS update  - installed under Programs and features (in control panel).<br>
&gt;So now ADFS is completely gone!<br>
<br>
</div>What does that have to do with Office 365? How would it know anything<br>
about what you did or didn&#39;t do on your own server? If it&#39;s been told to<br>
use ADFS and the only way to fix that is by doing what he has told you to<br>
do, then I guess that&#39;s what you have to do.<br>
<div class=""><br>
&gt;Now the issue about metadata file. I have following in our<br>
&gt;relying-party.xml<br>
</div><div class="">&gt;That is the reason I am talking about SAML i.e. FederationMetaDataUrl.<br>
<br>
</div>What does Shibboleth&#39;s own configuration have to do with a setting inside<br>
Office 365? The answer is nothing.<br>
<div class=""><br>
&gt;My understanding is that having FederationMetadataUrl defines which<br>
&gt;metadata to read and then follow the links mentioned in it, isn&#39;t it?<br>
<br>
</div>Apparently that isn&#39;t how Office 365 works. If it doesn&#39;t support metadata<br>
for SAML, then that&#39;s the reality. It sounds to me like the very fact that<br>
it&#39;s asking for a URL for metadata is apparently a sign that your service<br>
is not set up to use SAML, but WS-Federation.<br>
<div class=""><br>
&gt;I have made federation changes couple of times from Managed to federated<br>
&gt;as you have suggested but that FederationMetadataUrl comes back each time<br>
&gt;I federate and supply federation commands in one go. It comes<br>
&gt;automatically.<br>
<br>
</div>He told you that &quot;federated&quot; in their speak does not mean SAML. So you&#39;re<br>
essentially repeating the same error over and over again. He didn&#39;t tell<br>
you, ever, to change from managed to federated. Seemed like he said the<br>
opposite to me.<br>
<div class=""><br>
&gt;I have also restarted the system to start again after removing ADFS role<br>
&gt;and dependencies (updates).<br>
<br>
</div>How does restarting your system impact theirs? It can&#39;t.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><font face="tahoma, sans-serif"><b>Farzan Qureshi</b> | Network Administrator &amp; Help-desk Support | Rosmini College | (09) 487 0 530</font>
</div></div>

<br>
<font style="font-family:Verdana" size="1">This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager (<span style="font-weight:bold;font-style:italic"><a href="mailto:admin@rosmini.school.nz" target="_blank">admin@rosmini.school.nz</a></span>). Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, the recipient should check this email and any attachments for the presence of viruses. <span style="font-weight:bold">Rosmini College</span> accepts no liability for any damage caused by any virus transmitted by this email.</font>