<div dir="ltr">Hello,<div>Here at Oakland University Qualtrics provided us with a metadata file to load rather than using the InCommon one.  Example  entityID="<a href="https://oakland.az1.qualtrics.com/">https://oakland.az1.qualtrics.com/</a>".  It uses signing and encryption in the metadata file.</div><div>We made no changes to attribute-filter.xml or replyingparty.xml</div><div><br></div><div>Everything is working fine here.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Mar 16, 2018 at 7:56 AM, Losen, Stephen C. (scl) <span dir="ltr"><<a href="mailto:scl@virginia.edu" target="_blank">scl@virginia.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi folks,<br>
<br>
Qualtrics is an InCommon member and publishes their SP metadata.  We (Univ. of Virginia) are also an InCommon member with published IDP metadata, and we load the InCommon metadata aggregate into our IDP.<br>
<br>
We integrated our IDP with Qualtrics a year or so ago with no issues, only needed to add a filter to attribute-filter.xml  I think their SP uses simplesamlphp.  The entityID is <a href="https://virginia.az1.qualtrics.com/." rel="noreferrer" target="_blank">https://virginia.az1.<wbr>qualtrics.com/.</a>..<br>
<br>
Recently Qualtrics asked us to integrate with a new SP whose entityID is <a href="https://az1.qualtrics.com" rel="noreferrer" target="_blank">https://az1.qualtrics.com</a> .  So I modified our attribute-filter.xml to match the new entityID.  However, login to the new SP failed on the SP side after successful login to our IDP.  Qualtrics says that the assertion needs to be signed.<br>
<br>
Looking at the IDP wiki, I believe the default behavior for the SAML2 browser profile is to sign the response and not sign the assertion.  We have not changed this in our relying-party.xml.<br>
<br>
I suggested that Qualtrics should add WantAssertionsSigned="true" to their metadata, but the InCommon metadata management form does not appear to allow that.<br>
<br>
Now it looks like I need to put an override in relying-party.xml which I would prefer not to do.  So I am dragging my feet a bit on this, Qualtrics is working just fine with the old SP. I suggested that they modify their new SP to require signed responses, not assertions.<br>
<br>
Looking at the InCommon metadata file, it appears that Qualtrics has integrated with a large number of higher eds.  So this change will impact a large number of their customers if they insist on signed assertions.<br>
<br>
In case I am forced to add an override for Qualtrics to our relying-party.xml, has anyone else done this already? I obviously need to sign assertions, but do I need to explicitly not sign responses?<br>
<br>
Thanks,<br>
<br>
Stephen C. Losen<br>
ITS - Systems and Storage<br>
University of Virginia<br>
<a href="mailto:scl@virginia.edu">scl@virginia.edu</a>    434-924-0640<br>
<span class="HOEnZb"><font color="#888888"><br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div>Lee Foltz</div><div>Oakland University - UTS</div><div>Senior Identity Systems Engineer</div><div> </div><div>248-370-2675</div></div>
</div>