<div dir="ltr">Thank you all very much for your assistance.<div><br></div><div>Nate:</div><div><br></div><div>Its not the actual AuthnRequest that I'm trying to generate but the SAML response once the AuthnRequest is complete</div><div><br></div><div>Scott:</div><div><br></div><div>That worked ... or at least the SAML response wasn't returned.  Thanks!</div><div><br></div><div>Peter:</div><div><br></div><div>I would SO love to do that .  Unfortunately, the vendor says "no, you have to do it this way".  The department that wants this SSO connection goes to my boss and my boss says "do it".  I would really like to get to a point where I can make some of these SPs jump through arbitrary "hoops", just because I feel like it.</div><div><br></div><div>Michael:</div><div><br></div><div>You are correct.</div><div><br></div><div>Thanks again,</div><div>Mike </div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jun 21, 2017 at 8:56 AM, Domingues, Michael D <span dir="ltr"><<a href="mailto:michael-domingues@uiowa.edu" target="_blank">michael-domingues@uiowa.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div>


<div dir="ltr">
<div id="m_-2103361676052349279x_divtagdefaultwrapper" dir="ltr" style="font-size:11pt;color:#000000;font-family:Calibri,Helvetica,sans-serif">
<p>Based on the phrasing of the initial request, I'm about 90% confident that the vendor in question here is Photoshelter. If that's indeed the case, when integrating with them, we had success at Iowa by pushing back and insisting that they enable SP-initiated
 SSO and test things in the conventional manner.</p>
<p><br>
</p>
<p>Michael, if this is the case, feel free to contact me off-list and I can provide some more details.<br>
</p>
</div>
<hr style="display:inline-block;width:98%">
<div id="m_-2103361676052349279x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Peter Schober <<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>><br>
<b>Sent:</b> Wednesday, June 21, 2017 5:45:56 AM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
<b>Subject:</b> Re: Manually Generate a SAML Response</font>
<div> </div>
</div>
</div><div><div class="h5">
<font size="2"><span style="font-size:10pt">
<div class="m_-2103361676052349279PlainText">* Michael Dahlberg <<a href="mailto:olgamirth@gmail.com" target="_blank">olgamirth@gmail.com</a>> [2017-06-20 22:26]:<br>
> I have what I think is a unique problem.  I'm working with a SP that wants<br>
> to validate our IdP.  In so doing, they want us to POST a web document to<br>
> their test site which contains three fields: a base64 encoded SAML2<br>
> response, the base64 encoded version of our Shibboleth X509 cert, and our<br>
> entityId.<br>
<br>
Maybe just ask them to stop being silly, support SAML 2.0 Metadata (to<br>
learn your IDP's cert, among other things) and provide a way to<br>
actually test logins to their SP using your IDP, then they'll get all<br>
that anyway. Just a thought.<br>
-peter<br>
-- <br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div>
</span></font>
</div></div></div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>