<html>
  <head>
    <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    We recently got idp 3 working for our Google Apps accounts.  Here is
    what I know:<br>
    <br>
    Added this to relying-party.xml in the
    shibboleth.RelyingPartyOverrides section.<br>
    <br>
            <bean parent="RelyingPartyByName"
    c:relyingPartyIds="google.com"><br>
                <property name="profileConfigurations"><br>
                    <list><br>
                        <bean parent="SAML2.SSO"
    p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified"
    p:encryptAssertions="false" /><br>
                    </list><br>
                </property><br>
            </bean><br>
    <br>
    <br>
    Added this to metadata-providers.xml<br>
    <br>
        <MetadataProvider id="GoogleMD" <br>
                      xsi:type="FilesystemMetadataProvider" <br>
                      xmlns="urn:mace:shibboleth:2.0:metadata"<br>
                     
    metadataFile="%{idp.home}/metadata/google-metadata.xml"/><br>
    <br>
    Added this to the saml-nameid.xml file in the
    shibboleth.SAML2NameIDGenerators section<br>
    <br>
            <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<br>
               
    p:format="urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified"<br>
                p:attributeSourceIds="#{ {'principal','uid'} }" /><br>
    <br>
    Hopefully I remembered all the steps but I may have missed
    something.  Hope that helps anyway.<br>
    <br>
        Thanks,<br>
            Dan Oachs<br>
            Gustavus Adolphus College<br>
    <br>
    <br>
    <br>
    <div class="moz-cite-prefix">On 04/13/2016 05:22 AM, Dave Perry
      wrote:<br>
    </div>
    <blockquote
      cite="mid:33299E3AD0404D4399856B9C1A828CF201414505AB@QGEXDB2.HCUK.local"
      type="cite">
      <meta http-equiv="Context-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 14 (filtered
        medium)">
      <div class="WordSection1">
        <p class="MsoNormal">I am utterly confused (nothing new there,
          but I’ll attempt to explain this one).</p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal">I have a relying-party entry which I
          believe others have used:</p>
        <p class="MsoNormal">                                <bean
          parent="RelyingPartyByName" c:relyingPartyIds="google.com"></p>
        <p class="MsoNormal">            <property
          name="profileConfigurations"></p>
        <p class="MsoNormal">                <list></p>
        <p class="MsoNormal">                        <bean
          parent="SAML2.SSO"
          p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
          p:encryptAssertions="false" /></p>
        <p class="MsoNormal">                </list></p>
        <p class="MsoNormal">            </property></p>
        <p class="MsoNormal">        </bean></p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal">I have a request from google in my log
          which asks for NameID as unspecified:</p>
        <p class="MsoNormal"><samlp:AuthnRequest</p>
        <p class="MsoNormal">   
AssertionConsumerServiceURL=<a class="moz-txt-link-rfc2396E" href="https://www.google.com/a/hull-college.ac.uk/acs"><font color="red"><b>MailScanner has detected a possible fraud attempt from "www.google.com" claiming to be</b></font> "https://www.google.com/a/hull-college.ac.uk/acs"</a></p>
        <p class="MsoNormal">   
          ID="achibhchkpnnlacecgddfgbpfdallakncgfgofab"
          IsPassive="false"</p>
        <p class="MsoNormal">    IssueInstant="2016-04-13T09:39:51Z"</p>
        <p class="MsoNormal">   
          ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</p>
        <p class="MsoNormal">    ProviderName="google.com" Version="2.0"
          xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"></p>
        <p class="MsoNormal">    <saml:Issuer
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">google.com</saml:Issuer></p>
        <p class="MsoNormal">    <samlp:NameIDPolicy
          AllowCreate="true"
          Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"/></p>
        <p class="MsoNormal"></samlp:AuthnRequest></p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal">And google’s own metadata download (taken
          from the GA admin control panel) which has a weird entityID of
          <a moz-do-not-send="true"
            href="https://accounts.google.com/o/saml2?idpid=C04au2c47">https://accounts.google.com/o/saml2?idpid=C04au2c47</a></p>
        <p class="MsoNormal">Which specifies emailAddress as the NameID
          policy (somewhat contradictory to the request the IdP gets):</p>
        <p class="MsoNormal"><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat></p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal">My error log says there is no entry to
          handle entityID google.com in relying-party:</p>
        <p class="MsoNormal">2016-04-13 10:39:52,256 - DEBUG
          [org.opensaml.saml.metadata.resolver.impl.AbstractMetadataResolver:334]
          - Metadata backing store does not contain any
          EntityDescriptors with the ID: google.com</p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal">Even editing the metadata file they
          provide, to the following first line:</p>
        <p class="MsoNormal"><md:EntityDescriptor
          xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
          entityID="google.com"
          validUntil="2021-04-12T08:53:16.000Z"></p>
        <p class="MsoNormal">Doesn’t work.</p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal">Any suggestions appreciated.</p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal">Thanks,</p>
        <p class="MsoNormal">Dav</p>
        <p class="MsoNormal"> </p>
        <p class="MsoNormal"><span>_________________________________________________</span></p>
        <p class="MsoNormal"><span>Dave Perry<br>
            eLearning Technologist, Hull College Group<br>
            <br>
            Room L34 - Queens Gardens Library<br>
            Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG<br>
            Extension 2230 / Direct Dial 01482 381930</span></p>
        <p class="MsoNormal"><span> </span></p>
        <p class="MsoNormal"><b><span>* Need a fast reply? Try
              <a moz-do-not-send="true"
                href="mailto:elearning@hull-college.ac.uk">elearning@hull-college.ac.uk</a>
              *</span></b></p>
        <p class="MsoNormal"> </p>
      </div>
      <div> <span><a moz-do-not-send="true"
            href="http://www.hull-college.ac.uk/about-us/stakeholders-newsletter">The
            Review Newsletter</a></span>�</div>
      <div><br>
        This message is sent in confidence for the addressee� <span>only.
          �It may contain confidential or sensitive�</span> <span>information.
          �The contents are not to be disclosed�</span> <span>to anyone
          other than the addressee. �Unauthorised�</span> <span>recipients
          are requested to preserve this�</span> <span>confidentiality
          and to advise us of any errors in�</span> <span>transmission.
          �Any views expressed in this message�</span> <span>are solely
          the views of the individual and do not�</span> <span>represent
          the views of the College. �Nothing in this�</span> <span>message
          should be construed as creating a contract.</span> </div>
      <div> <br>
      </div>
      <div> Hull College Group owns the email infrastructure, including
        the contents. </div>
      <div> <br>
      </div>
      <div> Hull College Group is committed to sustainability, please
        reflect before printing this email. </div>
      <div>
        <hr> </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <br>
  </body>
</html>