<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>Hi members,</div><div>Some days ago I started with IdP3. My goal is to implement IdP to provide authentication based on our product's identity store.</div><div>Currently I have reached authentication by configuring metadata-providers.xml with SP's metadata. I use
<a href="http://samltest.id">samltest.id</a>
for testing purpose. <br></div><div><br></div><div>Another testing SP is <a href="http://sptest.iamshowcase.com">sptest.iamshowcase.com</a> doesn't provide own metadata. </div><div>One of the real SPs is CyberArk PVWA. It also doesn't provide own metadata - only the following knowledge:</div><div>- SAML2 is supported<br></div><div>- ACS URL<br></div><div>- NameIDFormat must be specified as urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</div><div>- IdP must return the user name inside NameID tag<br></div><div>- IdP must provide Issuer, IdP Certificate and IdP login URL <br></div><div>- IdP must be set to accept non signed requests</div><div>- IdP's configured 'secure hash algorithm' is either SHA1 or SHA256</div><div><br></div><div>I ask you push me somehow to understand a roadmap:</div><div>1) How to make Shib IdP and metadata-<b>less </b>SP friends?</div><div>2) How to force the IdP to return
the user name inside NameID tag with
NameIDFormat
set to
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified </div><div><br></div><div>I really hope on your help,</div><div>Thanks,</div><div>Jake<br>
</div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div></div></div></div></div></div>