<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px"><div id="yui_3_16_0_1_1454033580784_60806"><span id="yui_3_16_0_1_1454033580784_60852">> </span>And SAML? And federation?</div><div id="yui_3_16_0_1_1454033580784_60805"><div id="yui_3_16_0_1_1454033580784_60873"> </div><div id="yui_3_16_0_1_1454033580784_60950">    Yes, this is all pretty new to me.  My background is in Unix, since all of this seems to be AD related it's been outside of my sphere.  But now I need to know it.</div><div id="yui_3_16_0_1_1454033580784_60975"><br></div><div id="yui_3_16_0_1_1454033580784_60976">    Right now we have a goal to get Microsoft web store integrated with our Shibboleth IDP.  The documentation seems to assume that I know things that apparently I don't.  Testshib.org tells us our IDP is working, but we're at a lost how to get MS Web Store accessing it.</div><div><br></div><div>Regards</div><div id="yui_3_16_0_1_1454033580784_61023">-Bob<br></div></div><div id="yui_3_16_0_1_1454033580784_60798" class="signature"><div id="yui_3_16_0_1_1454033580784_60797">--<br>Bob Lamothe<br>robert_lamothe@yahoo.com<br>KB1BOB<br>603-918-6336<br><br></div></div> <div class="qtdSeparateBR"><br><br></div><div style="display: block;" class="yahoo_quoted"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 13px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir="ltr"><font face="Arial" size="2"> On Thursday, January 28, 2016 1:53 PM, "Cantor, Scott" <cantor.2@osu.edu> wrote:<br></font></div>  <br><br> <div class="y_msg_container">>     I'm fairly new to Shibboleth, 2 months ago I'd never heard about it.<br clear="none"><br clear="none">And SAML? And federation? Most of what you're talking about aren't Shibboleth things, though Shibboleth is more an exception among SAML implementations in using metadata exhaustively.<br clear="none"><br clear="none">> We're trying to add an external web site to OUR IDP.  Our IDP is registered<br clear="none">> with InCommon.  Reading about adding SPs it tells us to create a key,<br clear="none">> generate a CSR from the key, and receive the cert from InCommon.<br clear="none"><br clear="none">No, I don't know what you're reading, but that's not true. You're also going to have to be clearer about whose SP you're talking about.<br clear="none"><br clear="none">InCommon and other federations, which are essentially unique to higher ed (not 100% but close enough) is a mechanism for brokering the metadata between systems typically operated by different organizations. You consume a signed metadata aggregate to obtain metadata for lots of SPs at once, and you have to convince organizations operating SPs that are business partners to join the federation and register their metadata with it so you can do so in those cases.<br clear="none"><br clear="none">For SPs that don't do so, you have a problem that has nothing to do with Shibboleth: obtaining metadata for the SPs, dealing with how/why to trust it, and dealing with how to maintain it. That's the value proposition of the federations. In the real world, organizations email metadata, trust it blindly, and hope it never changes. We developed a model to address those problems. People have vastly different opinions about the scale of the problems and the need for an alternative.<div class="yqt5666889508" id="yqtfd39861"><br clear="none"><br clear="none">> After pouring over the docs, this procedure seems to be the procedure for<br clear="none">> adding a home grown SP, a website that I stood up and wish to authenticate<br clear="none">> against our IDP.  Is this correct?</div><br clear="none"><br clear="none">Literally, no, it's not the process for anything. Shibboleth favors a trust model that involves nothing but self-signed certificates issued locally. There's no sending a CSR anywhere. So again, don't know what you're referring to.<br clear="none"><br clear="none">The difference with a self-operated SP is that managing that metadata is a totally different scale of problem because you can usually get it much easier and have mechanisms to deal with maintaining it. Many IdPs just script the generation of the metadata or have local tools to manage it.<br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none"><br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><div class="yqt5666889508" id="yqtfd04269"><br clear="none"></div><br><br></div>  </div> </div>  </div></div></body></html>