<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div class="">Admittedly I didn't even look at the logs - as I would be surprised to find anything in there that wasn't obvious if the Shibboleth IdP was the cause (eg missing metadata, incorrect entityID, not sending the expected attribute). That's right Shibboleth
 does what it says on the box. ADFS is a little trickier - but there is enough instructions in the "<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop#MicrosoftInterop-ADFSv3(2012r2)" class="">Using Shibboleth IdP as the authentication
 source for ADFS</a>" section on that page for what is being attempted.</div>
<div class="">
<div class=""><br class="">
</div>
<div class="">For ADFSv3, you don't need to inject the cookie - if you don't it only makes the end-user flow annoying - but it all still works. That being said I would recommend injecting the cookie - love making life for those end-users easier. </div>
<div class=""><br class="">
</div>
<div class="">For errors, I generally operate on the principal that the issue exists wherever you see an error message in the web browser. Except for a few circumstances this seems apply.</div>
<div class=""><br class="">
</div>
<div class="">
<div class="">Cheers</div>
<div class="">Aaron</div>
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On 24 Feb 2016, at 7:05 AM, Michael A Grady <<a href="mailto:mgrady@unicon.net" class="">mgrady@unicon.net</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div class=""><br class="">
<blockquote type="cite" class="">On Feb 23, 2016, at 1:42 PM, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" class="">cantor.2@OSU.EDU</a>> wrote:<br class="">
<br class="">
<blockquote type="cite" class="">But really I can't see it being that different to setup than the notes here:<br class="">
<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop" class="">https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop</a><br class="">
</blockquote>
<br class="">
Most of that is ADFSv2 era information, I couldn't say if anything has changed.<br class="">
<br class="">
<blockquote type="cite" class="">Most of the configuration in that doco was on the ADFS side - not the<br class="">
Shibboleth side (shibboleth only needed metadata and attribute-release). I<br class="">
believe it's still the same SAML version between IdPv2 and v3 - so that should<br class="">
not cause problems.<br class="">
</blockquote>
<br class="">
It depends if you're trying to make MS understand "typical" SAML defaults from Shibboleth or have Shibboleth provide Microsoft's "creative" choices. But otherwise no, there's nothing significantly new with Shibboleth.<br class="">
<br class="">
Either way, the log that was posted is basically just the IdP issuing a response to the ADFS system. If that's "wrong" then you have to know what ADFS thinks is wrong with it to go any further.<br class="">
<br class="">
-- Scott<br class="">
<br class="">
</blockquote>
<br class="">
The config in ADFS is really not different, from what I've seen,  from ADFSv2 to ADFSv3, in terms of telling it about the IdP (giving it metadata) and putting in Claims config. The biggest change is that IIS/.asp scripts are no longer in the picture for ADFSv3,
 so what you have available to tweak as far as avoiding the ADFS discovery page is more limited. Pretty much need a load balancer that can inject a cookie inbound to ADFS (or perhaps a proxy in front of ADFS that does the same thing.)<br class="">
<br class="">
--<br class="">
Michael A. Grady<br class="">
IAM Architect, Unicon, Inc.<br class="">
<br class="">
-- <br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a></div>
</div>
</blockquote>
</div>
<br class="">
</div>
</div>
</div>
<span style="font-size: 9.0pt; font-family: 'Calibri'; "><em><strong><br>
Important Notice:</strong> The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete
 it and any attachments immediately and advise the sender by return email or telephone.<br>
<br>
Deakin University does not warrant that this email and any attachments are error or virus free.</em></span>
</body>
</html>