<div dir="ltr">One more thing. In the integration process I didn't create a specific relying party configuration for this SP, but instead consume their metadata. <div><br></div><div>In their metadata they include the next info:</div><div><br></div><div>....</div><div><div><SPSSODescriptor WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"></div><div><span class="" style="white-space:pre">        </span><KeyDescriptor use="encryption"></div><div><span class="" style="white-space:pre">                </span><KeyInfo xmlns="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div><div><span class="" style="white-space:pre">                        </span><X509Data></div><div><span class="" style="white-space:pre">                                </span><X509Certificate></div><div><span class="" style="white-space:pre">                                        </span>MII...</div><div><span class="" style="white-space:pre">                                </span></X509Certificate></div><div><span class="" style="white-space:pre">                        </span></X509Data></div><div><span class="" style="white-space:pre">                </span></KeyInfo></div><div><span class="" style="white-space:pre">        </span></KeyDescriptor></div><div><span class="" style="white-space:pre">                </span><KeyDescriptor use="signing"></div><div><span class="" style="white-space:pre">                        </span><KeyInfo xmlns="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div><div><span class="" style="white-space:pre">                                </span><X509Data></div><div><span class="" style="white-space:pre">                                        </span><X509Certificate></div><div><span class="" style="white-space:pre">                                                </span>MII...</div><div><span class="" style="white-space:pre">                                        </span></X509Certificate></div><div><span class="" style="white-space:pre">                                </span></X509Data></div><div><span class="" style="white-space:pre">                </span></KeyInfo></div><div><span class="" style="white-space:pre">        </span></KeyDescriptor></div><div><span class="" style="white-space:pre">        </span><SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://adfs.domain/adfs/ls/">https://adfs.domain/adfs/ls/</a>"/></div><div><span class="" style="white-space:pre">        </span><SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://adfs.domain/adfs/ls/">https://adfs.domain/adfs/ls/</a>"/></div><div><span class="" style="white-space:pre">        </span><NameIDFormat></div><div><span class="" style="white-space:pre">                </span>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</div><div><span class="" style="white-space:pre">        </span></NameIDFormat></div><div><span class="" style="white-space:pre">        </span><NameIDFormat></div><div><span class="" style="white-space:pre">                </span>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</div><div><span class="" style="white-space:pre">        </span></NameIDFormat></div><div><span class="" style="white-space:pre">        </span><NameIDFormat></div><div><span class="" style="white-space:pre">                </span>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</div><div><span class="" style="white-space:pre">        </span></NameIDFormat></div><div><span class="" style="white-space:pre">        </span><AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://adfs.domain/adfs/ls/">https://adfs.domain/adfs/ls/</a>" index="0" isDefault="true"/></div><div><span class="" style="white-space:pre">        </span><AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="<a href="https://adfs.domain/adfs/ls/">https://adfs.domain/adfs/ls/</a>" index="1"/></div><div><span class="" style="white-space:pre">        </span><AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://adfs.domain/adfs/ls/">https://adfs.domain/adfs/ls/</a>" index="2"/></div><div></SPSSODescriptor></div></div><div>....</div><div><br></div><div><br></div><div>So I'm guessing I'm not using their correct AssertionConsumerService (either POST or redirect) but instead I'm using an endpoint that only understand WS-Federation, right?</div><div><br></div><div>Another question: Why after the Ws-Federation URL is resolved and the end-user reauthenticates, the process is correctly done, I mean the AssertionConsumerService is displayed in the URL address bar and the end-user is send to the Sp's app?</div><div><br></div><div>Best,</div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Jan 22, 2015 at 10:27 AM, Thomas Jones <span dir="ltr"><<a href="mailto:thomas.jones.g@gmail.com" target="_blank">thomas.jones.g@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Thanks Scott for the response.<div><br></div><div>That means that I have to go the ADFS and change the endopoint of the SP's app that Shib is using to send the assertion, in order to use an endpoint that's actually saml and not ws-federation, right?<br><br>Thanks,<div><div class="h5"><br><br>On Thursday, January 22, 2015, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 1/22/15, 2:27 PM, "Thomas Jones" <<a>thomas.jones.g@gmail.com</a>> wrote:<br>
<br>
<br>
><br>
>I've seen that when my external app sends the respond to Shib's Idp and<br>
>this sends the respond to the ADFS, this one tries to access the next URL<br>
>(but later on it sends the user back to my external app, to repeat the<br>
>authentication process, as I have just<br>
> mentioned):<br>
><br>
><br>
><a href="https://adfs-domain/adfs/ls/?wa=wsignin1.0&wtrealm=https%3a%2f%2appcomain" target="_blank">https://adfs-domain/adfs/ls/?wa=wsignin1.0&wtrealm=https%3a%2f%2appcomain</a>.<br>
>com%2fapp.internet%2f&wfresh=5&wctx=rm%3d0%26id%3dpassive%26ru%3d%252fapp.<br>
>internet%252fHome%252fStart&wct=2015-01-22T00%3a15%3a24Z<br>
<br>
That's WS-Federation, not SAML. Assuming you didn't already know that.<br>
<br>
>But after the user has repeated for the second time the authentication,<br>
>the previous URL is not showed at all. Is this a miss configuration from<br>
>the ADFS or Shib?<br>
<br>
Has nothing to do with Shibboleth.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a>users-unsubscribe@shibboleth.net</a><br>
</blockquote></div></div></div>
</blockquote></div><br></div>