<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
{font-family:"Lucida Sans Unicode";
panose-1:2 11 6 2 3 5 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
h1
{mso-style-priority:9;
mso-style-link:"Heading 1 Char";
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:24.0pt;
font-family:"Times New Roman","serif";
font-weight:bold;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:"Courier New";}
span.EmailStyle19
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.Heading1Char
{mso-style-name:"Heading 1 Char";
mso-style-priority:9;
mso-style-link:"Heading 1";
font-family:"Calibri","sans-serif";
font-weight:bold;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Pager Duty also sent me this. Which they don’t seem to be much help in getting this configured.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<h1 style="mso-margin-top-alt:3.75pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:21.0pt">
<span style="font-size:16.5pt;color:#333333">While we couldn't tell you exactly how to make the changes, the following is the information you would need to configure Shibboleth with us.<o:p></o:p></span></h1>
<p style="mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:16.5pt">
<span style="font-size:10.5pt;font-family:"Lucida Sans Unicode","sans-serif";color:#2B2E2F">Entity ID= "<subdomain>.pagerduty.com"
<br>
ACS URL = "<a href="https://%3csubdomain%3e.pagerduty.com/sso/saml/consume">https://<subdomain>.pagerduty.com/sso/saml/consume</a>"<o:p></o:p></span></p>
<p style="mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:16.5pt">
<span style="font-size:10.5pt;font-family:"Lucida Sans Unicode","sans-serif";color:#2B2E2F">We expect the NameID claim as a 1.1 format email address. Specifically, it will look something like this: <Subject><NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"><a href="mailto:matt@example.com">matt@example.com</a></NameID><o:p></o:p></span></p>
<h1 style="mso-margin-top-alt:3.75pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:21.0pt">
<span style="font-size:16.5pt;color:#333333">There's no need to encrypt the responses as they are sent over HTTPS.<o:p></o:p></span></h1>
<p style="mso-margin-top-alt:11.25pt;margin-right:0in;margin-bottom:11.25pt;margin-left:0in;line-height:16.5pt">
<span style="font-size:10.5pt;font-family:"Lucida Sans Unicode","sans-serif";color:#2B2E2F">Please let me know if you have any additional questions.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> Cahill, Charles (GE Appliances)
<br>
<b>Sent:</b> Thursday, June 11, 2015 3:36 PM<br>
<b>To:</b> 'users@shibboleth.net'<br>
<b>Subject:</b> Re: Re: Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">So I have made all of the changes Peter recommended in this thread.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><a href="http://shibboleth.net/pipermail/users/2015-June/021856.html">http://shibboleth.net/pipermail/users/2015-June/021856.html</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I still seem to be getting the below error:<o:p></o:p></p>
<p class="MsoNormal" style="line-height:12.0pt"><span style="font-size:10.5pt;font-family:"Courier New";color:black">15:25:32.777 [http-bio-8080-exec-10] DEBUG e.i.m.s.i.a.p.UsernamePasswordLoginServlet - Successfully authenticated user xxxxxxxx<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:12.0pt"><span style="font-size:10.5pt;font-family:"Courier New";color:black">15:25:32.778 [http-bio-8080-exec-10] DEBUG e.i.m.s.i.authn.AuthenticationEngine - Returning control to authentication engine<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:12.0pt"><span style="font-size:10.5pt;font-family:"Courier New";color:black">15:25:32.778 [http-bio-8080-exec-10] DEBUG e.i.m.s.idp.util.HttpServletHelper - LoginContext key cookie was not present in request<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:12.0pt"><span style="font-size:10.5pt;font-family:"Courier New";color:black">15:25:32.778 [http-bio-8080-exec-10] WARN e.i.m.s.i.authn.AuthenticationEngine - No login context available, unable to return to authentication
engine<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:12.0pt"><span style="font-size:10.5pt;font-family:"Courier New";color:black">15:25:32.892 [http-bio-8080-exec-10] DEBUG e.i.m.s.idp.util.HttpServletHelper - LoginContext key cookie was not present in request<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:12.0pt"><span style="font-size:10.5pt;font-family:"Courier New";color:black">15:25:32.892 [http-bio-8080-exec-10] DEBUG e.i.m.s.idp.ui.ServiceContactTag - No relying party, nothing to display<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">May I inquire again into what the login URL is that I would be giving the 3<sup>rd</sup> party PagerDuty application or how it should be formatted?<o:p></o:p></p>
<p class="MsoNormal">I currently gave them this <a href="https://%7b$myidp%7d/idp/Authn/UserPassword">
https://{$myidp}/idp/Authn/UserPassword</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>