<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Gill Sans MT";
panose-1:2 11 5 2 2 1 4 2 2 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">I realize that others have posted a desire to get PowerFAIDS NetPartner SSO working with Shibboleth’s SAML implementation. In November of 2014, mrahman posted instructions for doing this with Shib 2.4.2, and I recall having this work for
me (see <a href="http://shibboleth.net/pipermail/users/2014-November/018121.html">
http://shibboleth.net/pipermail/users/2014-November/018121.html</a>). However, I have not had success in implementing NetParter SSO with Shibboleth 3. Based on my logs (in debug mode), my hangup at present seems to be that “no relying party configurations
ae applicable”, even though I have the relying party configured. Following is my idp-process log:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">---BEGIN LOG---<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,533 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.CheckMessageVersionHandler'
on INBOUND message context<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,533 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,533 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml1.binding.impl.SAML1ArtifactRequestIssuerHandler'
on INBOUND message context<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLProtocolAndRoleHandler'
on INBOUND message context<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler'
on INBOUND message context<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler'
on INBOUND message context<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:132] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching RelyingPartyContext based on SAML peer NetPartner<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,548 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:293] - Resolving relying party configuration<o:p></o:p></p>
<p class="MsoNormal">...(non relevant lines removed)…<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,564 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:305] - Checking if relying party configuration EntityNames[https://mynetpartnerhost.myuniversity.edu,] is applicable<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,564 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:310] - Relying party configuration EntityNames[https:// mynetpartnerhost. myuniversity.edu,] is not applicable<o:p></o:p></p>
<p class="MsoNormal">2018-05-08 11:27:17,564 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:314] - No relying party configurations are applicable, returning the default configuration shibboleth.DefaultRelyingParty<o:p></o:p></p>
<p class="MsoNormal">---END LOG---<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I added the following bean to my relying-party.xml file to use the Spriden ID (from Banner) for NetPartner:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">---BEGIN BEAN---<o:p></o:p></p>
<p class="MsoNormal"> <bean parent="RelyingPartyByName" c:relyingPartyIds="https://mynetpartnerhost.myuniversity.edu"><o:p></o:p></p>
<p class="MsoNormal"> <property name="profileConfigurations"><o:p></o:p></p>
<p class="MsoNormal"> <list><o:p></o:p></p>
<p class="MsoNormal"> <bean parent="SAML2.SSO"<o:p></o:p></p>
<p class="MsoNormal"> p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"<o:p></o:p></p>
<p class="MsoNormal"> p:encryptNameIDs="false"<o:p></o:p></p>
<p class="MsoNormal"> p:encryptAssertions="false"<o:p></o:p></p>
<p class="MsoNormal"> /><o:p></o:p></p>
<p class="MsoNormal"> </list><o:p></o:p></p>
<p class="MsoNormal"> </property><o:p></o:p></p>
<p class="MsoNormal"> </bean><o:p></o:p></p>
<p class="MsoNormal">---END BEAN---<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The following is my metadata file for netpartner:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">---BEGIN METADATA---<o:p></o:p></p>
<p class="MsoNormal"><EntityDescriptor entityID="NetPartner"<o:p></o:p></p>
<p class="MsoNormal"> xmlns="urn:oasis:names:tc:SAML:2.0:metadata"><o:p></o:p></p>
<p class="MsoNormal"> <SPSSODescriptor<o:p></o:p></p>
<p class="MsoNormal"> protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><o:p></o:p></p>
<p class="MsoNormal"> <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat><o:p></o:p></p>
<p class="MsoNormal"> <AssertionConsumerService index="1"<o:p></o:p></p>
<p class="MsoNormal"> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<o:p></o:p></p>
<p class="MsoNormal"> Location="https://mynetpartnerhost.myuniversity.edu/NetPartnerStudent/Logon.aspx"/><o:p></o:p></p>
<p class="MsoNormal"> </SPSSODescriptor><o:p></o:p></p>
<p class="MsoNormal"></EntityDescriptor><o:p></o:p></p>
<p class="MsoNormal">---END METADATA---<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I can provide additional configurations and/or complete files if helpful. Any ideas?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">By the way, if I can get NetPartner working with Shibboleth IdP v3, I will be happy to post results.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b><span style="font-family:"Gill Sans MT",sans-serif;color:#1F497D">Carl R. Daudt</span></b><span style="color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1F497D">Enterprise Applications Systems Analyst, Information Technology</span><span style="color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1F497D">Taylor University
<br>
236 W. Reade Avenue <br>
Upland, IN 46989 <br>
Office: 765-998-5313</span><span style="color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1F497D"><a href="mailto:crdaudt@taylor.edu"><span style="color:blue">crdaudt@taylor.edu</span></a></span><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif"><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<br>
<br>
<font face="Gill Sans Regular, Gill Sans MT, Trebuchet MS, Helvetica" color="888888" size="2">The information in this communication is intended solely for the individual or entity to whom it is addressed. It may contain confidential or legally privileged information.
If you are not the intended recipient, any disclosure, copying, distribution or reliance on the contents of this information is strictly prohibited, and may be unlawful. If you have received this communication in error, please notify us immediately by responding
to the sender of this email, and then delete it from your system. Taylor University is not liable for the inaccurate or improper transmission of the information contained in this communication or for any delay in its receipt.</font>
</body>
</html>