<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p>Evening all,</p>
<p><br>
</p>
<p>We have implemented Cirqlive and yes this process is as horrible as it sounds. Webex doesn't understand Saml and they don't support defining multiple identify providers (which would have resolved this issue). In the end creating and sharing a custom key
 and allowing impersonation of all users on the webex site by cirqlive is the only way to setup the integration while preventing cirqlive having access to your federated private key. (It certainly wasn't enjoyable or fun explaining this configuration to our
 security team)</p>
<p><br>
</p>
<p>IDP 3.3 supports the process here is an except from our relaying-party.xml file. </p>
<p><br>
</p>
<p><b>From relaying-party.xml</b></p>
<p><br>
</p>
<p></p>
<div> <!-- Configure fau's webex key --></div>
<div><span style="font-size:12pt"><bean id="ObnoxiousSecurityConfig" parent="shibboleth.DefaultSecurityConfiguration"></span></div>
<div>    <property name="signatureSigningConfiguration"></div>
<div>        <bean parent="shibboleth.SigningConfiguration.SHA256" p:signingCredentials-ref="shibboleth.WebexSigningCredential" /></div>
<div>    </property></div>
<div></bean></div>
<div><br>
</div>
<div>        <!-- WebEx http://www.webex.com/faulearn --></div>
<div>        <bean parent="RelyingPartyByName" c:relyingPartyIds="#{{ 'http://www.webex.com/faulearn', 'http://www.webex.com/fau' }}"></div>
<div>            <property name="profileConfigurations"></div>
<div>                <list></div>
<div>            <bean parent="Shibboleth.SSO" p:securityConfiguration-ref="ObnoxiousSecurityConfig" /></div>
<div>            <bean parent="SAML1.AttributeQuery" p:securityConfiguration-ref="ObnoxiousSecurityConfig" /></div>
<div>            <bean parent="SAML1.ArtifactResolution" p:securityConfiguration-ref="ObnoxiousSecurityConfig" /></div>
<div>            <bean parent="SAML2.ECP" p:securityConfiguration-ref="ObnoxiousSecurityConfig" /></div>
<div>            <bean parent="SAML2.Logout" p:securityConfiguration-ref="ObnoxiousSecurityConfig" /></div>
<div>            <bean parent="SAML2.AttributeQuery" p:securityConfiguration-ref="ObnoxiousSecurityConfig" /></div>
<div>            <bean parent="SAML2.ArtifactResolution" p:securityConfiguration-ref="ObnoxiousSecurityConfig" /></div>
<div>            <bean parent="SAML2.SSO" p:encryptAssertions="false" p:signResponses="false" p:signAssertions="true" p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" p:securityConfiguration-ref="ObnoxiousSecurityConfig"  /></div>
<div>                </list></div>
<div>            </property></div>
<div>        </bean></div>
<div><br>
</div>
<b>From credentials.xml</b>
<p></p>
<p><br>
</p>
<p></p>
<div>    <bean id="shibboleth.WebexSigningCredential"</div>
<div>        class="net.shibboleth.idp.profile.spring.factory.BasicX509CredentialFactoryBean"</div>
<div>        p:privateKeyResource="%{idp.signing.webex.key}"</div>
<div>        p:certificateResource="%{idp.signing.webex.cert}"</div>
<div>        p:entityId-ref="entityID" /></div>
<div>        </div>
<div>There are several adjustments that are required to saml-nameid.xml and attribute-resolver.xml to support webex. If you want those configurations please email me off list. </div>
<br>
<p></p>
<p><br>
</p>
<div id="x_Signature">
<div id="x_divtagdefaultwrapper" style="background-color:rgb(255,255,255); font-family:Calibri,Helvetica,sans-serif,EmojiFont,"Apple Color Emoji","Segoe UI Emoji",NotoColorEmoji,"Segoe UI Symbol","Android Emoji",EmojiSymbols,EmojiFont,"Apple Color Emoji","Segoe UI Emoji",NotoColorEmoji,"Segoe UI Symbol","Android Emoji",EmojiSymbols">
<div name="x_divtagdefaultwrapper" style="margin:0px">
<div style="background-color:rgb(255,255,255)">
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Rhian Resnick</span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:16px; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Assistant Director Middleware and HPC</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:16px; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Office of Information Technology</span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt"><br>
</span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Florida Atlantic University</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">777 Glades Road, CM22, Rm 173B</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Boca Raton, FL 33431</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Phone 561.297.2647</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Fax 561.297.0222</span></p>
<p class="x_x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt"> </span><span style="color:rgb(31,73,125); font-family:Calibri,sans-serif; font-size:11pt"><a href="https://hpc.fau.edu/wp-content/uploads/2015/01/image.jpg" id="LPNoLP" style="border:0px; font-family:Arial,Helvetica,sans-serif; font-size:13px; line-height:21px; margin:0px; padding:0px; vertical-align:baseline; color:rgb(0,102,204); text-decoration:none; background-color:rgb(239,239,239)"><img alt="image" class="x_alignnone x_size-full x_wp-image-498" style="border:0px; font-style:inherit; font-variant:inherit; font-weight:inherit; line-height:inherit; margin:5px; padding:0px; vertical-align:middle; max-width:100%; width:195px" src="http://hpc.fau.edu/wp-content/uploads/2015/01/image.jpg"></a></span></p>
</div>
</div>
</div>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Tom Scavo <trscavo@gmail.com><br>
<b>Sent:</b> Tuesday, August 22, 2017 10:36:26 AM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Integrating idp3 with cirqlive</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On Mon, Aug 21, 2017 at 9:54 PM, Joseph Fischetti<br>
<Joseph.Fischetti@marist.edu> wrote:<br>
> I've been asked to look into integrating cirqlive with our existing IDP 3<br>
> installation. Cirqlive adds a link between Sakai and webex sso.<br>
<br>
Apparently that "link" you speak of is not SAML Web Browser SSO since<br>
CirQlive MEETS is not browser-facing (according to the document you<br>
sent).<br>
<br>
> During my<br>
> research I found that cirqlive expects the private key of our IDP so that it<br>
> can sign the assertions that it sends to WebEx.<br>
<br>
No rational IdP operator would do that...<br>
<br>
> Obvious security concerns aside, when I reached out to cirqlive for<br>
> clarification, I received the following PDF in reply.  It seems that, given<br>
> architecture 1 (page 3), they feel that sharing the idp's private key is<br>
> okay.<br>
<br>
Well then they don't understand how SAML works. If they possess a copy<br>
of your private SAML signing key, they could impersonate your IdP at<br>
will. Such a key must be considered compromised.<br>
<br>
> They also reference using separate keys for different SPs, which as<br>
> far as im aware, isn't possible with IDP 3.<br>
<br>
I don't know about that but for the sake of argument let's suppose<br>
that's possible. You can't publish the corresponding public key<br>
certificate in federation metadata since then you're right back where<br>
you started (i.e., complete compromise). So maintenance of that key is<br>
necessarily out-of-band. For a compromised key, that's bad news.<br>
<br>
That's actually the least of your worries. Assuming the private key is<br>
securely transmitted to the 3rd party in the first place, that signing<br>
key is still compromised since the 3rd party can impersonate any of<br>
your users logging into webex. Worse, if they lose control of the<br>
private key, you're right back where you started...complete and utter<br>
compromise.<br>
<br>
> Does anybody else have experience with this?<br>
<br>
I hope not ;-)<br>
<br>
Tom<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>