<div dir="ltr">I got a reply from the IDP,<div>what they are saying is , they will be doing a IDP initiated SSO and therefore no need for  SingleSignOnService attribute.</div><div>Is this the case?</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Dec 2, 2016 at 1:39 PM, Sam Jacob <span dir="ltr"><<a href="mailto:skjacob@gmail.com" target="_blank">skjacob@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Thanks Tom for the info.</div><div class="gmail_extra"><div><div class="h5"><br><div class="gmail_quote">On Fri, Dec 2, 2016 at 12:49 PM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Fri, Dec 2, 2016 at 1:33 PM, Sam Jacob <<a href="mailto:skjacob@gmail.com" target="_blank">skjacob@gmail.com</a>> wrote:<br>
><br>
> no endpoints are provided.<br>
<br>
That's weird. A service provider needs to know where to send the<br>
AuthnRequest. Without a trusted IdP endpoint location, there's no way<br>
to begin the SAML flow.<br>
<span><br>
> The metadata contains just these entries<br>
> x509, attributes and contact info.<br>
<br>
</span>Of those, the certificate is most important, since you need that to<br>
verify the signature on the response and/or the assertion the IdP<br>
ultimately sends to you.<br>
<div class="m_3647728334491354392HOEnZb"><div class="m_3647728334491354392h5"><br>
Tom<br>
<br>
> On Fri, Dec 2, 2016 at 12:27 PM, Tom Scavo <<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>> wrote:<br>
>><br>
>> On Fri, Dec 2, 2016 at 12:54 PM, Liam Hoekenga <<a href="mailto:liamr@umich.edu" target="_blank">liamr@umich.edu</a>> wrote:<br>
>> > Acc'd to the SAML spec, the IDPSSODescriptor element must include at<br>
>> > least<br>
>> > one SingleSignOnService:<br>
>> ><br>
>> > <a href="https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf" rel="noreferrer" target="_blank">https://docs.oasis-open.org/se<wbr>curity/saml/v2.0/saml-metadata<wbr>-2.0-os.pdf</a><br>
>> > 2.4.3 Element <IDPSSODescriptor><br>
>> > <SingleSignOnService> [One or More]<br>
>> > One or more elements of type EndpointType that describe endpoints that<br>
>> > support the profiles of<br>
>> > the Authentication Request protocol defined in [SAMLProf]. All identity<br>
>> > providers support at least<br>
>> > one such endpoint, by definition. The ResponseLocation attribute MUST be<br>
>> > omitted.<br>
>><br>
>> Yes, that's correct, there must be at least one SingleSignOnService<br>
>> endpoint.<br>
>><br>
>> Question for Sam: If there's no SingleSignOnService endpoint, what<br>
>> endpoints are there? (I just have to know :)<br>
>><br>
>> Thanks,<br>
>><br>
>> Tom<br>
>><br>
>> > On Fri, Dec 2, 2016 at 11:43 AM, Sam Jacob <<a href="mailto:skjacob@gmail.com" target="_blank">skjacob@gmail.com</a>> wrote:<br>
>> >><br>
>> >> IDP provided their metadata file and it's missing the<br>
>> >> SingleSignOnService<br>
>> >> tag in the XML file.<br>
>> >> and shib is giving an error: "metadata instance failed manual<br>
>> >> validation<br>
>> >> checking: IDPSSODescriptor must have at least one SingleSignOnService.<br>
>> >> "<br>
>> >><br>
>> >> is "SingleSignOnService" a required attribute?<br>
>> >> Can SSO work without "SingleSignOnService" ?<br>
>> >><br>
>> >> thanks<br>
>> >><br>
>> >> --<br>
>> >> Sam Jacob<br>
>> >><br>
>> >> --<br>
>> >> To unsubscribe from this list send an email to<br>
>> >> <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
>> ><br>
>> ><br>
>> ><br>
>> > --<br>
>> > To unsubscribe from this list send an email to<br>
>> > <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
>> --<br>
>> To unsubscribe from this list send an email to<br>
>> <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
><br>
><br>
><br>
><br>
> --<br>
> Sam Jacob<br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div></div></div><span class="HOEnZb"><font color="#888888">-- <br><div class="m_3647728334491354392gmail_signature" data-smartmail="gmail_signature">Sam Jacob</div>
</font></span></div>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">Sam Jacob</div>
</div>