<div dir="ltr">I don&#39;t have experience with zoom, but I do have ample experience with other SPs that can&#39;t accept encrypted assertions.  If they don&#39;t accept encrypted assertions, then it&#39;s perfectly normal to not have any certs in their metadata.  Shib should load it up just fine.  Don&#39;t forget to adjust your relying-party.xml and be explicit about no encryption for that SP if your defaults are to always encrypt.<div><br>Dave</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Jan 22, 2015 at 9:14 PM, Leung, Warren <span dir="ltr">&lt;<a href="mailto:wleung@it.ucla.edu" target="_blank">wleung@it.ucla.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div style="word-wrap:break-word;color:rgb(0,0,0);font-size:14px;font-family:Calibri,sans-serif">
<div style="font-family:Calibri,sans-serif">Hi,</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">We have a department that currently has a license for Zoom a cloud based video conferencing and communications and they would like to integrate with our IdP.  Does anyone have any experiencing integrating with
 them?</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">After reading the documentation and speaking with their support I ran into a couple of issues.</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">They do not support encrypted assertions.  From what I’ve seen there have been a lot of vendor applications that have their own SAML implementations that do not support encrypted assertions.  So I guess this is
 more of a comment than a question/issues.</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">This is my stupid question, but looking at the metadata they provided it appears that it does not contain any certificate information.  Their support provided the following &quot;We do receive iDP cert but we not require
 SP cert as we do not sign requests and response sent to the Identity Provider today. The SSO sign-in page is transmitted over https only.”  The schema allows for 0 KeyDescriptors, but I have never run into a scenario where a SP had 0.  Does anyone have any
 experience working with this?  I am not even sure if this will work and if signing isn’t enabled it just doesn’t seem secure.  The metadata I am referring to is below.</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div>
<p style="margin:0px">&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;&lt;md:EntityDescriptor xmlns:md=&quot;urn:oasis:names:tc:SAML:2.0:metadata&quot; entityID=&quot;<a href="http://ucla.zoom.us" target="_blank">ucla.zoom.us</a>&quot;&gt;&lt;md:SPSSODescriptor AuthnRequestsSigned=&quot;false&quot; WantAssertionsSigned=&quot;true&quot; protocolSupportEnumeration=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;&gt;&lt;md:SingleLogoutService
 Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; Location=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>&quot; ResponseLocation=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>&quot;/&gt;&lt;md:SingleLogoutService
 Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>&quot; ResponseLocation=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>&quot;/&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:persistent&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName&lt;/md:NameIDFormat&gt;&lt;md:AssertionConsumerService
 Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; Location=&quot;<a href="https://ucla.zoom.us/saml/SSO" target="_blank">https://ucla.zoom.us/saml/SSO</a>&quot; index=&quot;0&quot; isDefault=&quot;true&quot;/&gt;&lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;
 Location=&quot;<a href="https://ucla.zoom.us/saml/SSO" target="_blank">https://ucla.zoom.us/saml/SSO</a>&quot; index=&quot;1&quot;/&gt;&lt;/md:SPSSODescriptor&gt;&lt;/md:EntityDescriptor&gt;</p>
<p style="margin:0px"><br>
</p>
<p style="margin:0px">Thanks</p><span class="HOEnZb"><font color="#888888">
<p style="margin:0px"><br>
</p>
<p style="margin:0px">Warren</p>
</font></span></div>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div></div>
</div>