<div dir="ltr">Salesforce provided metadata:<div>...</div><div>  <md:SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><br></div><div>...</div><div><br></div><div>I changed AuthnRequestsSigned to false and got Shibboleth logon page by going to </div><div><a href="https://iis.authasas.local/idp/profile/SAML2/Unsolicited/SSO?providerId=https://authtest.my.salesforce.com">https://iis.authasas.local/idp/profile/SAML2/Unsolicited/SSO?providerId=https://authtest.my.salesforce.com</a></div><div><br></div><div>Now I have another issue from Salesforce SAML validator:</div><div><br></div><div>Subject: AAdzZWNyZXQxKb+vKRzExCggvlsBj11cPO1e4b8KwJYq42uI5hcOaLP04CqFfzHS3zmHQiOPqvg5F9kn9oKHG1Ec0g88Mt0QlgImEP3lwJ3tHK75bi9yE8S/2RFQIoEMAg1wNZmeA7DG2+HI</div><div>Unable to map the subject to a Salesforce.com user </div><div><br></div><div>AssertionId: _57a74f9acf0ac809af03319e395d1a50</div><div><br></div><div>Now I am working on this issue.</div><div> </div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">2015-05-07 16:55 GMT+03:00 Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 5/7/15, 9:32 AM, "Peter Schober" <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br>
<br>
>* Alexander Galilov <<a href="mailto:alexander.galilov@gmail.com">alexander.galilov@gmail.com</a>> [2015-05-07 14:56]:<br>
>> 2015-05-07 15:49:33,070 - ERROR<br>
>> [org.opensaml.saml.saml2.binding.security.impl.SAML2AuthnRequestsSignedSecurityHandler:75]<br>
>> - SPSSODescriptor for entity ID '<a href="https://authtest.my.salesforce.com" target="_blank">https://authtest.my.salesforce.com</a>'<br>
>> indicates AuthnRequests must be signed, but inbound message was not signed<br>
><br>
>If that vendor indeed communicates (via SAML metadata) that the<br>
>authentication requests it generates need to by signed by it, then<br>
>they better start generating authentication requests.<br>
>I'd open a support request for them to get SP-initiated SSO working,<br>
>instead of messing around with IDP-initiated.<br>
<br>
</span>Salesforce *is* SP initiated, it works as well as any other bad implementation. I believe their metadata is broken and indicates it's going to sign the requests, but doesn't. That's certainly the cause of the error anyway, which should be pretty self-evident.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>