<div dir="ltr">Thanks Tom for the info.</div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Dec 2, 2016 at 12:49 PM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Fri, Dec 2, 2016 at 1:33 PM, Sam Jacob <<a href="mailto:skjacob@gmail.com">skjacob@gmail.com</a>> wrote:<br>
><br>
> no endpoints are provided.<br>
<br>
That's weird. A service provider needs to know where to send the<br>
AuthnRequest. Without a trusted IdP endpoint location, there's no way<br>
to begin the SAML flow.<br>
<span class=""><br>
> The metadata contains just these entries<br>
> x509, attributes and contact info.<br>
<br>
</span>Of those, the certificate is most important, since you need that to<br>
verify the signature on the response and/or the assertion the IdP<br>
ultimately sends to you.<br>
<div class="HOEnZb"><div class="h5"><br>
Tom<br>
<br>
> On Fri, Dec 2, 2016 at 12:27 PM, Tom Scavo <<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>> wrote:<br>
>><br>
>> On Fri, Dec 2, 2016 at 12:54 PM, Liam Hoekenga <<a href="mailto:liamr@umich.edu">liamr@umich.edu</a>> wrote:<br>
>> > Acc'd to the SAML spec, the IDPSSODescriptor element must include at<br>
>> > least<br>
>> > one SingleSignOnService:<br>
>> ><br>
>> > <a href="https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf" rel="noreferrer" target="_blank">https://docs.oasis-open.org/<wbr>security/saml/v2.0/saml-<wbr>metadata-2.0-os.pdf</a><br>
>> > 2.4.3 Element <IDPSSODescriptor><br>
>> > <SingleSignOnService> [One or More]<br>
>> > One or more elements of type EndpointType that describe endpoints that<br>
>> > support the profiles of<br>
>> > the Authentication Request protocol defined in [SAMLProf]. All identity<br>
>> > providers support at least<br>
>> > one such endpoint, by definition. The ResponseLocation attribute MUST be<br>
>> > omitted.<br>
>><br>
>> Yes, that's correct, there must be at least one SingleSignOnService<br>
>> endpoint.<br>
>><br>
>> Question for Sam: If there's no SingleSignOnService endpoint, what<br>
>> endpoints are there? (I just have to know :)<br>
>><br>
>> Thanks,<br>
>><br>
>> Tom<br>
>><br>
>> > On Fri, Dec 2, 2016 at 11:43 AM, Sam Jacob <<a href="mailto:skjacob@gmail.com">skjacob@gmail.com</a>> wrote:<br>
>> >><br>
>> >> IDP provided their metadata file and it's missing the<br>
>> >> SingleSignOnService<br>
>> >> tag in the XML file.<br>
>> >> and shib is giving an error: "metadata instance failed manual<br>
>> >> validation<br>
>> >> checking: IDPSSODescriptor must have at least one SingleSignOnService.<br>
>> >> "<br>
>> >><br>
>> >> is "SingleSignOnService" a required attribute?<br>
>> >> Can SSO work without "SingleSignOnService" ?<br>
>> >><br>
>> >> thanks<br>
>> >><br>
>> >> --<br>
>> >> Sam Jacob<br>
>> >><br>
>> >> --<br>
>> >> To unsubscribe from this list send an email to<br>
>> >> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
>> ><br>
>> ><br>
>> ><br>
>> > --<br>
>> > To unsubscribe from this list send an email to<br>
>> > <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
>> --<br>
>> To unsubscribe from this list send an email to<br>
>> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
><br>
><br>
><br>
><br>
> --<br>
> Sam Jacob<br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">Sam Jacob</div>
</div>