<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:11pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p>Based on the phrasing of the initial request, I'm about 90% confident that the vendor in question here is Photoshelter. If that's indeed the case, when integrating with them, we had success at Iowa by pushing back and insisting that they enable SP-initiated
 SSO and test things in the conventional manner.</p>
<p><br>
</p>
<p>Michael, if this is the case, feel free to contact me off-list and I can provide some more details.<br>
</p>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Wednesday, June 21, 2017 5:45:56 AM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Manually Generate a SAML Response</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">* Michael Dahlberg <olgamirth@gmail.com> [2017-06-20 22:26]:<br>
> I have what I think is a unique problem.  I'm working with a SP that wants<br>
> to validate our IdP.  In so doing, they want us to POST a web document to<br>
> their test site which contains three fields: a base64 encoded SAML2<br>
> response, the base64 encoded version of our Shibboleth X509 cert, and our<br>
> entityId.<br>
<br>
Maybe just ask them to stop being silly, support SAML 2.0 Metadata (to<br>
learn your IDP's cert, among other things) and provide a way to<br>
actually test logins to their SP using your IDP, then they'll get all<br>
that anyway. Just a thought.<br>
-peter<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>