<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:11pt;color:#000000;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p>Pretty sure this is the reverse. The Cirrus gateway (someone hop in and correct me if I'm wrong) allows campuses to use Social Login (Facebook, etcetera) and tie it in to their on-premise IAM environment. Workplace by Facebook is much like Microsoft's Yammer,
in that it's a social network for the workplace (in so far as that's a thing), which acts as an SP, with the ability to use federated identities from campus IdPs for login.<br>
</p>
<br>
<br>
<div style="color: rgb(0, 0, 0);">
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" color="#000000" face="Calibri, sans-serif"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Bryan Wooten <bryan.wooten@utah.edu><br>
<b>Sent:</b> Wednesday, November 2, 2016 6:44 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: [Ext] Re: WORKPLACE BY FACEBOOK integration</font>
<div> </div>
</div>
<div>
<div>Is this not what Dedra is doing?</div>
<div><br>
</div>
<div><a href="http://www.cirrusidentity.com/gateway/" id="LPlnk103781" previewremoved="true">http://www.cirrusidentity.com/gateway/</a></div>
<div><br>
</div>
<div><u>-Bryan</u></div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; border-bottom:medium none; border-left:medium none; padding-bottom:0in; padding-left:0in; padding-right:0in; border-top:#b5c4df 1pt solid; border-right:medium none; padding-top:3pt">
<span style="font-weight:bold">From: </span>IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>><br>
<span style="font-weight:bold">Reply-To: </span>"<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>" <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Date: </span>Wednesday, November 2, 2016 at 5:26 PM<br>
<span style="font-weight:bold">To: </span>"<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>" <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Subject: </span>[Ext] Re: WORKPLACE BY FACEBOOK integration<br>
</div>
<div><br>
</div>
<div>
<div>
<div dir="ltr">I was provided:
<div>
<p class="gmail-p1">Audience URL <a href="https://www.facebook.com/company/1077798945674112">https://www.facebook.com/company/1077798945674112</a></p>
<p class="gmail-p1">Recipient URL <a href="https://alaska.facebook.com/work/saml.php">https://alaska.facebook.com/work/saml.php</a></p>
<p class="gmail-p1">ACS (Assertion Consumer Service) URL <a href="https://alaska.facebook.com/work/saml.php">https://alaska.facebook.com/work/saml.php</a></p>
<p class="gmail-p1">I'm guessing Recipient is entityID</p>
<p class="gmail-p1">db</p>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Wed, Nov 2, 2016 at 3:22 PM, Cantor, Scott <span dir="ltr">
<<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex; border-left:1px #ccc solid; padding-left:1ex">
<span class="">> WORKPLACE BY FACEBOOK apparently deploys simpleSAML PHP / SAML 2.0<br>
> for SSO but provides minimal documentation. No metadata or certificate, no<br>
> attribute requirements, etc.<br>
<br>
</span>The bare minimum is the endpoint, if the implementation is broken and doesn't check Audience conditions. That's not per se a security hole unless they also don't check the Recipient attribute, but that takes some dedicated pen-testing to determine. I
have done integrations that did not have an entityID and worked like that, though after reporting it I was able to get them to configure one (in their view, the audience to check for).<br>
<br>
When in doubt, stick whatever the user identifier has to be in the NameID and see if it works, assuming you know the endpoint to create the metadata around.<br>
<br>
It is less work to just experiment, which takes a few minutes, than worry about getting all the details right.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote>
</div>
<br>
</div>
</div>
</div>
</span></div>
</div>
</div>
</body>
</html>