<div dir="ltr"><div class="gmail_default" style="font-family:courier new,monospace">I also did just notice that we had to downgrade the signature signing algorithm to sha-1 and the assertion is unencrypted. Also for some reason if the nameid isn't email, it doesn't like that either. Although it was never clear as to what it actually did with the nameid. Once we got through that it seemed to plug in rather easily, I can as the tech on the banner side what settings we set there if there is interest.</div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><font face="monospace, monospace">Jeffrey E. Crawford<br>Enterprise Service Team<a href="mailto:jeffreyc@ucsc.edu" target="_blank"></a></font><div><font face="monospace, monospace">    ^         ^</font></div><div><font face="monospace, monospace">   / \  ^    / \    ^</font></div><div><font face="monospace, monospace">  /   \/ \  /   \  / \</font></div><div><font face="monospace, monospace"> /        \/     \/   \</font></div><div><font face="monospace, monospace">/                      \</font></div><div><font face="monospace, monospace"><br></font></div><div><font face="monospace, monospace">You have been assigned this mountain to prove to others that it *can* be moved.</font></div></div></div></div></div></div></div>
<br><div class="gmail_quote">On Thu, Nov 2, 2017 at 3:34 PM, Tom O'Neill <span dir="ltr"><<a href="mailto:oneill@sigcorp.com" target="_blank">oneill@sigcorp.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Yes, the UDC_IDENTIFIER attribute is required but isn't the tricky part of the configuration.<br>
<br>
I've had issues with the SAML 2.0 configuration for the Banner 9 components.<br>
The last time I worked on a full SAML 2.0 stack we had SSO Manager, Application Navigator and a SSB module working but Admin Pages was trouble.<br>
I'd imagine it can be done - we were working with Ellucian Ethos Identity at the time, which isn't my preferred IdP but it didn't seem to be a mature integration yet.<br>
<span class="im HOEnZb"><br>
Thanks,<br>
<br>
    Tom O'Neill<br>
<br>
-----Original Message-----<br>
</span><span class="im HOEnZb">From: users [mailto:<a href="mailto:users-bounces@shibboleth.net">users-bounces@<wbr>shibboleth.net</a>] On Behalf Of Jorj Bauer<br>
Sent: Thursday, November 02, 2017 3:32 PM<br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Subject: Re: Banner 9 SAML<br>
<br>
</span><div class="HOEnZb"><div class="h5">We had a small host of tiny details that had to be divined. The UDCID is critical and reasonably obvious.<br>
<br>
I think our initial CAS setup was about 3 weeks of various staff from IAM or the ERP team. Our SAML attempts are probably the same order of magnitude.<br>
<br>
Sent from my iPhone<br>
<br>
On Nov 2, 2017, at 14:53, Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br>
<br>
>>> We did get it to work but it's very custom, we had to create the following<br>
>> resolver which is released only to Banner:<br>
><br>
> If all it takes is a custom attribute then people need to recalibrate what they think "doesn't work easily" means. You're not going to get much better from a whole lot of vendors.<br>
><br>
> -- Scott<br>
><br>
> --<br>
> For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>