<div dir="ltr">Hi,<div><br></div><div>Some time back, I have worked integrated Shibboleth Idp 2.4 with Zendesk. I guess It can help you in your issue.</div><div><br></div><div><a href="http://www.waheedtechblog.com/2015/10/configure-shibboleth-idp-to-achieve.html">http://www.waheedtechblog.com/2015/10/configure-shibboleth-idp-to-achieve.html</a><br></div><div><br></div><div>Regards,</div><div>Abdul Waheed.</div><div class="gmail_extra"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div></div></div></div>
<br><div class="gmail_quote">On Sat, Apr 8, 2017 at 8:14 AM, Hwei Chan <span dir="ltr"><<a href="mailto:hwei@nextidea.co.nz" target="_blank">hwei@nextidea.co.nz</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
  

    
  
  <div bgcolor="#FFFFFF" text="#000000">
    Hi
    <br>
    <br>
    Just wondering if anyone has successfully integrated Zendesk to
    Shibboleth IdP?
    <br>
    <br>
    The aim is to get SSO working from Zendesk (and a few other third
    party services) to our Shibboleth IdP instance.
    <br>
    <br>
    I'm new to Shibboleth and SAML in general but have managed to get
    SSO working with a few sample SAML service providers (including
    TestShib).
    <br>
    <br>
    However, I'm having trouble getting the setup for Zendesk working.
    <br>
    <br>
    I've tried to follow the instructions provided by Zendesk here:
    <br>
    <br>
    <a class="m_9170372135499469046moz-txt-link-freetext" href="https://support.zendesk.com/hc/en-us/articles/203663676" target="_blank">https://support.zendesk.com/<wbr>hc/en-us/articles/203663676</a>
    <br>
    <br>
    They seem to require at least:
    <br>
    <br>
    * Remote login URL for the SAML server (Shibboleth)
    <br>
    * SHA2 fingerprint for the SAML certificate from the SAML server
    <br>
    <br>
    The only thing I've found regarding the Zendesk SP metadata is:
    <br>
    <br>
    <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
    <br>
    <EntityDescriptor entityID="<a href="http://your_subdomain.zendesk.com" target="_blank">your_subdomain.<wbr>zendesk.com</a>"
    xmlns="urn:oasis:names:tc:<wbr>SAML:2.0:metadata">
    <br>
        <SPSSODescriptor AuthnRequestsSigned="false"
    WantAssertionsSigned="true"
    protocolSupportEnumeration="<wbr>urn:oasis:names:tc:SAML:2.0:<wbr>protocol">
    <br>
<NameIDFormat>urn:oasis:names:<wbr>tc:SAML:1.1:nameid-format:<wbr>emailAddress</NameIDFormat>
    <br>
            <AssertionConsumerService index="1"
    Binding="urn:oasis:names:tc:<wbr>SAML:2.0:bindings:HTTP-POST" Location=<a class="m_9170372135499469046moz-txt-link-rfc2396E" href="https://accountname.zendesk.com/access/saml" target="_blank">"https://accountname.<wbr>zendesk.com/access/saml"</a>/>
    <!-- Note: replace 'accountname' with your Zendesk subdomain
    -->
    <br>
        </SPSSODescriptor>
    <br>
    </EntityDescriptor>
    <br>
    <br>
    The other SPs I've tried requires the IdP's metadata (which Zendesk
    doesn't seem to ask for) and the other SPs metadata seem to contain
    a lot more info then the above.
    <br>
    <br>
    I've tried a couple of things but none of them have worked.
    <br>
    <br>
    Would really appreciate any advise from the Shibboleth experts on
    the appropriate configuration required to get integration to work.
    <br>
    <br>
    Thanks in advance!
    <br>
    <br>
    Regards,
    <br>
    Hwei
  </div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div></div>