<html><head></head><body><div style="color:#000; background-color:#fff; font-family:Courier New, courier, monaco, monospace, sans-serif;font-size:16px"><div id="yui_3_16_0_ym19_1_1463067971340_15007"><?xml version="1.0" encoding="UTF-8" ?></div><div id="yui_3_16_0_ym19_1_1463067971340_15008"><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://compass.cudirect.com"></div><div id="yui_3_16_0_ym19_1_1463067971340_15009"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"></div><div id="yui_3_16_0_ym19_1_1463067971340_15010"> <md:KeyDescriptor use="signing"></div><div id="yui_3_16_0_ym19_1_1463067971340_15011"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"></div><div id="yui_3_16_0_ym19_1_1463067971340_15012"> <ds:X509Data></div><div id="yui_3_16_0_ym19_1_1463067971340_15013"> <ds:X509Certificate>a cert goes here</ds:X509Certificate></div><div id="yui_3_16_0_ym19_1_1463067971340_15033"> </ds:X509Data></div><div id="yui_3_16_0_ym19_1_1463067971340_15034"> </ds:KeyInfo></div><div id="yui_3_16_0_ym19_1_1463067971340_15035"> </md:KeyDescriptor></div><div id="yui_3_16_0_ym19_1_1463067971340_15036"> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat></div><div id="yui_3_16_0_ym19_1_1463067971340_15037"> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://compass.cudirect.com/account/samlrequest"/></div><div id="yui_3_16_0_ym19_1_1463067971340_15038"> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://compass.cudirect.com/account/samlrequest"/></div><div id="yui_3_16_0_ym19_1_1463067971340_15039"> </md:IDPSSODescriptor></div><div></div><div dir="ltr" id="yui_3_16_0_ym19_1_1463067971340_15040"></md:EntityDescriptor></div><div dir="ltr" id="yui_3_16_0_ym19_1_1463067971340_15040"><br></div><div dir="ltr" id="yui_3_16_0_ym19_1_1463067971340_15040">This was the first metadata they gave me and when that failed they sent it again sans the redirect stanza. My version of Shib is too old and does not use the SSO tag.</div> <div class="qtdSeparateBR"><br><br></div><div class="yahoo_quoted" style="display: block;"> <div style="font-family: Courier New, courier, monaco, monospace, sans-serif; font-size: 16px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir="ltr"><font size="2" face="Arial"> On Thursday, May 12, 2016 8:55 AM, "Cantor, Scott" <cantor.2@osu.edu> wrote:<br></font></div> <br><br> <div class="y_msg_container">> They require the authN to be signed and sent as POST, not GET. But even<br clear="none">> with just that one end point, Shib is still sending it as GET:<br clear="none"><br clear="none">Can't be the only endpoint in their metadata then, there's no other place it can get the information.<div class="yqt3716765934" id="yqtfd81518"><br clear="none"><br clear="none">> Is there a way to force this one entity to send as POST instead of GET?</div><br clear="none"><br clear="none">Fix the metadata or set the outgoingBindings property in the SSO element.<br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><div class="yqt3716765934" id="yqtfd31376"><br clear="none"></div><br><br></div> </div> </div> </div></div></body></html>