<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 16px; font-family: Calibri, sans-serif;">
<div><br>
</div>
<div>I have set up a version 3 IdP and am in the process of making the necessary changes to the V3 configurations to reflect what I currently have configured on the V2 IdP. One thing that I need to do is turn off encryption for specific vendor SP's. Below
is what I am using for the V2 configuration and the V3 configuration. However, the V3 configuration does not seem to work as expected. When I attempt to login to one of the SP's, I get a response similar to the following repeated over and over in the V3
IdP logs. </div>
<div><br>
</div>
<div>From what I can tell, the IdP successfully authenticates but the SP does not recognize the attribute as returned by the IdP; in a browser I can clearly see the message
<b>'user AAdzaBBxarzzawtssshe1zn3!! not found' </b>repeated over and over; this leads me to believe that the user attribute is still encoded (note the I actually see a string like 'AAdzaBBxarzzawtssshe1zn3!!' in the browser) . I believe that, as in version
2 , I need to somehow include the provider="<a href="https://login.emory.edu/idp/shibboleth">https://login.emory.edu/idp/shibboleth</a>" and the defaultSigningCredentialRef="IdPCredential" (of course this is only a guess at this point). Its probably somewhere
in the DOC's but I cannot seem to locate it. </div>
<div><br>
</div>
<div>Can someone provide an example of the version 3 configuration and if possible point me to the appropriate DOC's for IdP version 3? </div>
<div><br>
</div>
<div>Thanks in advance for any assistance.</div>
<div><br>
</div>
<div><b>(from version 3 IdP logs)</b></div>
<div>
<div>2015-10-16 07:53:46,229 - DEBUG [org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:220] - Setting RelayState parameter to: 'https://emory.service-now.com/navpage.do', encoded as 'https://emory.service-now.com/navpage.do'</div>
<div>2015-10-16 07:53:46,245 - INFO [Shibboleth-Audit.SSO:241] - 20151016T115346Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|SNC3769762114e9f795325b5a5a34e9f4ae|https://emory.service-now.com/|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://login.emory.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_e96a91240794402e2a903d03322647b3|ghall4|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|serialNumber,transientId|AAdzZWNyZXQx6yPgQZRUvqwu42dCaUDU5sr4QpGfkwk+UcFLgt57639oJ+UcNvYcaY1ejQSzed539zwLdYwVdcHOmn+h09zzq9TlMUjWi1AH2++pKp+WcGlslA/4v1Ka2BmNDwW7rhlTrH0F|_c54b44c552ec920aa18384f8f770c5cd</div>
</div>
<div><br>
</div>
<div><br>
</div>
<div><b>(working version 2 configuration for disabling encryption)</b></div>
<div>
<div> <RelyingParty id="https://emory.service-now.com/"</div>
<div> provider="https://login.emory.edu/idp/shibboleth"</div>
<div> defaultSigningCredentialRef="IdPCredential"></div>
<div> <ProfileConfiguration xsi:type="saml:SAML2SSOProfile" encryptAssertions="never" encryptNameIds="never" /></div>
<div> </RelyingParty></div>
</div>
<div><br>
</div>
<div>
<div> <RelyingParty id="apperian.com.:ssoDevelopment"</div>
<div> provider="https://login.emory.edu/idp/shibboleth"</div>
<div> defaultSigningCredentialRef="IdPCredential"></div>
<div> <ProfileConfiguration xsi:type="saml:SAML2SSOProfile" encryptAssertions="never" encryptNameIds="never" /></div>
<div> </RelyingParty></div>
</div>
<div><br>
</div>
<div><b>(not working version 3 configuration for disabling encryption)</b></div>
<div>
<div> <bean parent="RelyingPartyByName" c:relyingPartyIds="https://emory.service-now.com/" ></div>
<div> <property name="profileConfigurations"></div>
<div> <list></div>
<div> <bean parent="SAML2.SSO" p:encryptAssertions="false" /></div>
<div> </list></div>
<div> </property></div>
<div> </bean></div>
</div>
<div><br>
</div>
<div>
<div> <bean parent="RelyingPartyByName" c:relyingPartyIds="apperian.com"></div>
<div> <property name="profileConfigurations"></div>
<div> <list></div>
<div> <bean parent="SAML2.SSO" p:encryptAssertions="false" /></div>
<div> </list></div>
<div> </property></div>
<div> </bean></div>
</div>
<span id="OLK_SRC_BODY_SECTION">
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 16px; font-family: Calibri, sans-serif;">
<span id="OLK_SRC_BODY_SECTION">
<div bgcolor="#FFFFFF" text="#000000">
<pre class="moz-signature" cols="72"></pre>
</div>
</span></div>
</div>
</blockquote>
</span><br>
<hr>
<font face="Arial" color="Gray" size="1"><br>
This e-mail message (including any attachments) is for the sole use of<br>
the intended recipient(s) and may contain confidential and privileged<br>
information. If the reader of this message is not the intended<br>
recipient, you are hereby notified that any dissemination, distribution<br>
or copying of this message (including any attachments) is strictly<br>
prohibited.<br>
<br>
If you have received this message in error, please contact<br>
the sender by reply e-mail message and destroy all copies of the<br>
original message (including attachments).<br>
</font>
</body>
</html>