<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Matthew,
<div class=""><br class="">
</div>
<div class="">Thanks for the blog links, my Google-fu had not found them.</div>
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Feb 17, 2016, at 4:33 PM, Matthew Slowe <<a href="mailto:M.Slowe@kent.ac.uk" class="">M.Slowe@kent.ac.uk</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div style="font-family: Helvetica; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class="">
If you're doing ECP as well then the certificate you have on the HTTPS ECP endpoint needs to be trusted *and* has to match the certificate in your configured - therefore the certificate you use in the SAML assertion has to be a signed one (which then expires…)</div>
</div>
</blockquote>
<br class="">
</div>
<div>I never did validate whether ECP worked or not with my first setup. I stopped at logging into O365 via Shib.</div>
<div><br class="">
</div>
<div>So, to make sure I understand, getting ECP to work requires the TLS certificate be trusted (so signed by a commercial CA) and that the exact same certificate be used to sign the SAML responses?</div>
<br class="">
<div class="">-----<br class="">
Paul Hethmon<br class="">
Chief Software Architect<br class="">
<a href="mailto:paul.hethmon@clareitysecurity.com" class="">paul.hethmon@clareitysecurity.com</a><br class="">
<br class="">
</div>
<br class="">
</div>
</body>
</html>