<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body dir="auto">
<div>If you're doing ECP as well then the certificate you have on the HTTPS ECP endpoint needs to be trusted *and* has to match the certificate in your configured - therefore the certificate you use in the SAML assertion has to be a signed one (which then expires…)</div>
<div><br>
</div>
<div>I've written a few blog posts on the subject which may be of use:</div>
<div><br>
</div>
<div><a href="http://blogs.kent.ac.uk/unseenit/office365-and-shibboleth/">http://blogs.kent.ac.uk/unseenit/office365-and-shibboleth/</a></div>
<div><a href="http://blogs.kent.ac.uk/unseenit/simple-shibboleth-ecp-test/">http://blogs.kent.ac.uk/unseenit/simple-shibboleth-ecp-test/</a></div>
<div><a href="http://blogs.kent.ac.uk/unseenit/how-we-do-office365-authentication/">http://blogs.kent.ac.uk/unseenit/how-we-do-office365-authentication/</a></div>
<div><br>
</div>
<div>And more recently when our signing certificate really did come up for renewal… </div>
<div><a href="http://blogs.kent.ac.uk/unseenit/updating-trust-fabric-certificate-between-shibboleth-and-office365/">http://blogs.kent.ac.uk/unseenit/updating-trust-fabric-certificate-between-shibboleth-and-office365/</a></div>
<div><br>
</div>
<div>Hope they're useful!</div>
<div>Matthew<br>
<br>
<div>Sent from my mobile device.</div>
</div>
<div><br>
On 17 Feb 2016, at 19:22, Paul Hethmon <<a href="mailto:paul.hethmon@clareitysecurity.com">paul.hethmon@clareitysecurity.com</a>> wrote:<br>
<br>
</div>
<blockquote type="cite">
<div><span>So I found myself needing to set up Office 365 with my Shibboleth IdP. I had done this last fall and got it working but needed to move it to another domain/server.</span><br>
<span></span><br>
<span>Without commenting on how clueless MS support is, they are asking me to try a CA signed certificate for the SAML signing certificate (instead of the normal self-signed cert created at installation). So some questions in case someone else has had to bang
their head against the O365 wall:</span><br>
<span></span><br>
<span>1. If I put in a CA signed certificate as my public key, is there a need to include intermediate certificates? At least as far as my published IdP metadata.</span><br>
<span>2. MS support keeps wanting to see a Shib log file that is usually in /var/log/shibboleth/shibd.log. Isn’t that the default location for the Shib SP log file?</span><br>
<span>3. Any troubleshooting tips?</span><br>
<span></span><br>
<span>thanks,</span><br>
<span></span><br>
<span>Paul</span><br>
<span></span><br>
<span></span><br>
<span>-----</span><br>
<span>Paul Hethmon</span><br>
<span>Chief Software Architect</span><br>
<span><a href="mailto:paul.hethmon@clareitysecurity.com">paul.hethmon@clareitysecurity.com</a></span><br>
<span></span><br>
<span></span><br>
<span>-- </span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></span></div>
</blockquote>
</body>
</html>