<div dir="ltr">I don't have experience with zoom, but I do have ample experience with other SPs that can't accept encrypted assertions. If they don't accept encrypted assertions, then it's perfectly normal to not have any certs in their metadata. Shib should load it up just fine. Don't forget to adjust your relying-party.xml and be explicit about no encryption for that SP if your defaults are to always encrypt.<div><br>Dave</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Jan 22, 2015 at 9:14 PM, Leung, Warren <span dir="ltr"><<a href="mailto:wleung@it.ucla.edu" target="_blank">wleung@it.ucla.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div style="word-wrap:break-word;color:rgb(0,0,0);font-size:14px;font-family:Calibri,sans-serif">
<div style="font-family:Calibri,sans-serif">Hi,</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">We have a department that currently has a license for Zoom a cloud based video conferencing and communications and they would like to integrate with our IdP. Does anyone have any experiencing integrating with
them?</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">After reading the documentation and speaking with their support I ran into a couple of issues.</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">They do not support encrypted assertions. From what I’ve seen there have been a lot of vendor applications that have their own SAML implementations that do not support encrypted assertions. So I guess this is
more of a comment than a question/issues.</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div style="font-family:Calibri,sans-serif">This is my stupid question, but looking at the metadata they provided it appears that it does not contain any certificate information. Their support provided the following "We do receive iDP cert but we not require
SP cert as we do not sign requests and response sent to the Identity Provider today. The SSO sign-in page is transmitted over https only.” The schema allows for 0 KeyDescriptors, but I have never run into a scenario where a SP had 0. Does anyone have any
experience working with this? I am not even sure if this will work and if signing isn’t enabled it just doesn’t seem secure. The metadata I am referring to is below.</div>
<div style="font-family:Calibri,sans-serif"><br>
</div>
<div>
<p style="margin:0px"><?xml version="1.0" encoding="UTF-8"?><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="<a href="http://ucla.zoom.us" target="_blank">ucla.zoom.us</a>"><md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>" ResponseLocation="<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>"/><md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>" ResponseLocation="<a href="https://ucla.zoom.us/saml/SingleLogout" target="_blank">https://ucla.zoom.us/saml/SingleLogout</a>"/><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName</md:NameIDFormat><md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://ucla.zoom.us/saml/SSO" target="_blank">https://ucla.zoom.us/saml/SSO</a>" index="0" isDefault="true"/><md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="<a href="https://ucla.zoom.us/saml/SSO" target="_blank">https://ucla.zoom.us/saml/SSO</a>" index="1"/></md:SPSSODescriptor></md:EntityDescriptor></p>
<p style="margin:0px"><br>
</p>
<p style="margin:0px">Thanks</p><span class="HOEnZb"><font color="#888888">
<p style="margin:0px"><br>
</p>
<p style="margin:0px">Warren</p>
</font></span></div>
</div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div></div>
</div>