<div dir="ltr"><span class=""></span><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br><div bgcolor="#FFFFFF" text="#000000"><span class=""><blockquote type="cite">
      <pre>Without commenting on how clueless MS support is, they are asking me to try a CA signed certificate for the SAML signing certificate (instead of the normal self-signed cert created at installation). So some questions in case someone else has had to bang their head against the O365 wall:</pre>
    </blockquote>
    <br></span>
    I know literally zero about Office 365, so I have no idea how their
    trust works and what they really require.  Do you supply a metadata
    XML document?  Do you upload a key + other info to a mgmt UI on the
    MS side?  <span class=""></span></div></blockquote><div><br></div><div>no metadata XML, you upload a 1. domain, 2. url (binding), 3. ecp url (binding), 4. uri (entityID), 5. logout url, and 6. base64 encoded x509 cert. to my knowledge, O365 will only do signing, no encryption of the assertion.<br><br></div><div>-Rob<br><br></div><div> <br></div></div><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div></div>
</div></div>