<div dir="ltr">Hi Carl,<div><br></div><div>We've had NetPartner working for some time. My configuration notes says that NetPartner requires the NameID to be an email address but in unspecified format, because this is the match field to records in the back-end database. (I don't recall if this is a specific requirement or just that we specify email address as the match field in NP Manager (I don't have access to NP Manager config at the moment)). So this may or may not effect your use of the "Spriden ID" as the NameID.</div><div><br></div><div>In NP Manager we set the protocol binding to POST but the IdP URL to <a href="https://login.stolaf.edu/idp/profile/SAML2/Redirect/SSO">https://login.stolaf.edu/idp/profile/SAML2/Redirect/SSO</a> which seems to jibe with your config.</div><div><br></div><div>I do notice one difference in our configs: in our relying part override, we have set "p:securityConfiguration-ref="SHA1SecurityConfig". IIRC, when we upgraded to v3, NetPartner did not work until we added that line. Here are our relevant config bits:</div><div><br></div><div>metadata:</div><div><div><font face="monospace, monospace"><?xml version="1.0" encoding="UTF-8"?></font></div><div><font face="monospace, monospace"><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="NetPartner"></font></div><div><font face="monospace, monospace">        <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"></font></div><div><font face="monospace, monospace">                <md:AssertionConsumerService index="1" isDefault="true" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://blah.stolaf.edu/NetPartner/NetPartnerStudent/Logon.aspx">https://blah.stolaf.edu/NetPartner/NetPartnerStudent/Logon.aspx</a>" /></font></div><div><font face="monospace, monospace">        </md:SPSSODescriptor></font></div><div><font face="monospace, monospace"></md:EntityDescriptor></font></div></div><div><br></div><div>relying-party.xml:</div><div><div><font face="monospace, monospace">        <!-- Some SPs need nameid to be email address in format:unspecified. --></font></div><div><font face="monospace, monospace">        <bean parent="RelyingPartyByName" c:relyingPartyIds="#{{</font></div><div><font face="monospace, monospace">            'NetPartner',</font></div><div><font face="monospace, monospace">            '***.***.***',</font></div><div><font face="monospace, monospace">            '****.***.***'</font></div><div><font face="monospace, monospace">            }}"></font></div><div><font face="monospace, monospace">            <property name="profileConfigurations"></font></div><div><font face="monospace, monospace">                <list></font></div><div><font face="monospace, monospace">                    <bean parent="SAML2.SSO"</font></div><div><font face="monospace, monospace">                        p:encryptAssertions="false"</font></div><div><font face="monospace, monospace">                        p:encryptNameIDs="false"</font></div><div><font face="monospace, monospace">                        p:securityConfiguration-ref="SHA1SecurityConfig"</font></div><div><font face="monospace, monospace">                        p:nameIDFormatPrecedence="#{{'urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified'}}" /></font></div><div><font face="monospace, monospace">                    <ref bean="SAML2.Logout" /></font></div><div><font face="monospace, monospace">               </list></font></div><div><font face="monospace, monospace">            </property></font></div><div><font face="monospace, monospace">        </bean></font></div></div><div><br></div><div><br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr">On Fri, May 11, 2018 at 10:29 AM Daudt, Carl <<a href="mailto:crdaudt@taylor.edu">crdaudt@taylor.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="m_-2516367249560210220WordSection1">
<p class="MsoNormal">OK, I now have the following for my relying-part.xml configuration, which is getting me a lot further:<u></u><u></u></p>
<p class="MsoNormal">---BEGIN---<u></u><u></u></p>
<p class="MsoNormal">        <bean parent="RelyingPartyByName" c:relyingPartyIds="NetPartner"><u></u><u></u></p>
<p class="MsoNormal">            <property name="profileConfigurations"><u></u><u></u></p>
<p class="MsoNormal">                <list><u></u><u></u></p>
<p class="MsoNormal">                                                <bean parent="SAML2.SSO"<u></u><u></u></p>
<p class="MsoNormal">                                                                p:encryptAssertions="false"<u></u><u></u></p>
<p class="MsoNormal">                                                /><u></u><u></u></p>
<p class="MsoNormal">                </list><u></u><u></u></p>
<p class="MsoNormal">            </property><u></u><u></u></p>
<p class="MsoNormal">        </bean><u></u><u></u></p>
<p class="MsoNormal">---END---<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">My metadata is unchanged.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I am properly redirected to my CAS login screen (our Shibboleth configuration uses CAS for logins), and then I am redirected back to NetPartner, albeit with an “Invalid Single Sign On Response” message, which I will explain below.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">My shibboleth logs end with the following entry:<u></u><u></u></p>
<p class="MsoNormal">---BEGIN---<u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Lucida Console"">2018-05-11 10:38:59,599 - INFO [Shibboleth-Audit.SSO:241] - 20180511T143859Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|dcdgnhncfmpgmahebjiejlpbekfpgjmadbofekpb|NetPartner|<a href="http://shibboleth.net/ns/profiles/saml2/sso/browser%7Chttps://myshibbolethserver.myuniversity.edu/idp/shibboleth%7Curn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST%7C_2062f2d7c57e755b95757862a95dceab%7Ccrdaudt%7Curn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport%7CnetPartnerStudentID%7CAAdzZWNyZXQxYmLfPXBwREDYO4i78NsYwsnyDjrHRmXo+MXbxn5A2zzz4beCrAbfyrwNsPEbV04NSTKmJ6yIoVBFAizssJI3Dm6QhfxajQGO2ERY+iZ5d9Y=%7C_dc25b38190cd8aa953c635901fe5ab80%7C" target="_blank">http://shibboleth.net/ns/profiles/saml2/sso/browser|https://myshibbolethserver.myuniversity.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_2062f2d7c57e755b95757862a95dceab|crdaudt|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|netPartnerStudentID|AAdzZWNyZXQxYmLfPXBwREDYO4i78NsYwsnyDjrHRmXo+MXbxn5A2zzz4beCrAbfyrwNsPEbV04NSTKmJ6yIoVBFAizssJI3Dm6QhfxajQGO2ERY+iZ5d9Y=|_dc25b38190cd8aa953c635901fe5ab80|</a></span><u></u><u></u></p>
<p class="MsoNormal">---END---<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">My Net Partner logs indicate an ERROR that “SSO Response Digital Signature could not be validated”.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">In my Net Partner configuration, I have specified that the Public Key Certificate” for my IdP is my idp-encryption.crt file (I have also tried idp-signing.crt – to be honest, I am not sure which to use).  I have also specified that my IdP
 URL is <a href="https://myshibbolethserver.myuniversity.edu/idp/profile/SAML2/Redirect/SSO" target="_blank">
https://myshibbolethserver.myuniversity.edu/idp/profile/SAML2/Redirect/SSO</a> , my Protocol Binding is POST, and my Requested NameId Format is unspecified (other options include persistent, transient, emailAdress, and various other options).<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Any further suggestions?<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><b><span style="font-family:"Gill Sans MT",sans-serif;color:#1f497d">Carl R. Daudt</span></b><span style="color:#1f497d"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1f497d">Enterprise Applications Systems Analyst, Information Technology</span><span style="color:#1f497d"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1f497d">Taylor University
<br>
236 W. Reade Avenue <br>
Upland, IN  46989 <br>
Office:  765-998-5313</span><span style="color:#1f497d"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1f497d"><a href="mailto:crdaudt@taylor.edu" target="_blank"><span style="color:blue">crdaudt@taylor.edu</span></a></span><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif"><u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<br>
<br>
<font face="Gill Sans Regular, Gill Sans MT, Trebuchet MS, Helvetica" color="888888" size="2">The information in this communication is intended solely for the individual or entity to whom it is addressed. It may contain confidential or legally privileged information.
 If you are not the intended recipient, any disclosure, copying, distribution or reliance on the contents of this information is strictly prohibited, and may be unlawful. If you have received this communication in error, please notify us immediately by responding
 to the sender of this email, and then delete it from your system. Taylor University is not liable for the inaccurate or improper transmission of the information contained in this communication or for any delay in its receipt.</font>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><b>Tony Skalski</b></div><div dir="ltr">System Administrator | IT</div><div dir="ltr"><img src="https://docs.google.com/uc?export=download&id=0B8pehFb2jk1VTlJUMXNxQzlUZ0k&revid=0B8pehFb2jk1VR0ZGVzBjRksvU1NMQUdwSzNIa05Ea08ydjFFPQ" width="200" height="77"><br></div><div dir="ltr"><b>Office: </b><a href="javascript:void(0);" target="_blank">507-786-3227</a></div><div dir="ltr">1510 St. Olaf Avenue Northfield, MN 55057</div><div dir="ltr"><a href="http://stolaf.edu" target="_blank">stolaf.edu</a></div><div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>