<div dir="ltr"><div>Adobe Cloud appears to have similar 'shortfalls'. <br></div><div><br></div><div>We are seeing similar from recent vendors moving to the cloud --  cost savings?<br> </div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, 8 Aug 2019 at 15:10, Wessel, Keith <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">I've strongly hinted that they need to consider supporting encrypted assertions, and they claim they've added it to their roadmap.<br>
<br>
I've also recently learned that they plan to soon make the metadata retrievable from a URL for those who wish to dynamically reload it in their IdP. I strongly encouraged them to sign such metadata and make a signing cert securely available if they actually want to make this feature useful unlike some other vendors who I won't name here other than to say that they used to be earth's biggest bookstore.<br>
<br>
I do wish they would include the OID-style names for first and last name and mail in the mappings they look for by default, but our tests show that those have to be added as custom mappings. I do give them points for paying attention to SAML2 names instead of friendly names, though.<br>
<br>
Keith<br>
<br>
<br>
-----Original Message-----<br>
From: users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> On Behalf Of Paul B. Henson<br>
Sent: Thursday, August 8, 2019 4:56 PM<br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: RE: Linkedin learning<br>
<br>
> From: mat houser<br>
> Sent: Tuesday, July 30, 2019 12:24 PM<br>
> <br>
> I'm curious if anybody has gotten linkedin learning SSO working <br>
> properly with the Shibboleth IdP.<br>
<br>
We recently migrated from <a href="http://lynda.com" rel="noreferrer" target="_blank">lynda.com</a> to linked in learning. Other than the already mentioned annoying backpedal from federated metadata to ad hoc metadata (they say it's "more secure"), and the caveat that encryption must be disabled it was fairly straightforward. I believe links to the documentation have already been posted; I did have some confusion as to whether not they wanted the "friendly name" for the attribute or the urn -based name, when I initially put the wrong one I did get the same error as you. As I recall I had to put the urn.<br>
<br>
Also, another annoyance the documentation doesn't really discuss well; they really really really really really try to encourage new users to link their linked in learning account to their <a href="http://linkedin.com" rel="noreferrer" target="_blank">linkedin.com</a> account. The latter intentionally does not support SSO (they say for security reasons 8-/, they don't want an employer to be able to hijack and employees <a href="http://linkedin.com" rel="noreferrer" target="_blank">linkedin.com</a> account; who uses their work account for their primary <a href="http://linkedin.com" rel="noreferrer" target="_blank">linkedin.com</a> access???). If the two accounts are linked, after you authenticate via SSO, you then need to provide your local <a href="http://linkedin.com" rel="noreferrer" target="_blank">linkedin.com</a> username/password before you actually get in. This is very confusing for people who do SSO and then immediately see a username/password prompt :(.<br>
<br>
--<br>
Paul B. Henson  |  (909) 979-6361  |  <a href="http://www.cpp.edu/~henson/" rel="noreferrer" target="_blank">http://www.cpp.edu/~henson/</a> Operating Systems and Network Analyst  |  <a href="mailto:henson@cpp.edu" target="_blank">henson@cpp.edu</a> California State Polytechnic University  |  Pomona CA 91768<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>