<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">On 2/11/2020 8:32 AM, Lohr, Donald
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:38c6ae7a-8145-0273-afa6-755dcea0c671@jmu.edu">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      We have a new SP to configure and the vendor is not an InCommon
      member and states the following:<br>
      <br>
      <i>We support both Identify Provider or Service Provider initiated
        methods, as both are equally viable for us. We never provide the
        metadata file or URL. We only provide links such as the ACS URL
        or Entity ID. We also produce the login and logout URL but some
        IDPs don't require or use it. This is all unrelated to whether
        or not it is SP or IDP initiated.  </i>
      <div style="font-size: 12pt; color: rgb(0, 0, 0);
        background-color: rgb(255, 255, 255);"> <i><br>
        </i> </div>
      <i> </i>
      <div style="font-size: 12pt; color: rgb(0, 0, 0);
        background-color: rgb(255, 255, 255);"><i> Example:</i></div>
      <i> </i>
      <div style="font-size: 12pt; color: rgb(0, 0, 0);
        background-color: rgb(255, 255, 255);"><i> 1. Entity ID: <a
            class="moz-txt-link-freetext"
            href="https://portal.acme.com/saml/metadata/xxxxxxxxxx"
            moz-do-not-send="true">https://portal.acme.com/saml/metadata/xxxxxxxxxx</a></i><i><br>
        </i>
        <div><i>2. ACS URL: <a class="moz-txt-link-freetext"
              href="https://identity" moz-do-not-send="true">https://identity</a></i><i>.acme</i><i>.com/api/authenticate/</i><i>xxxxxxxxxx</i>
        </div>
        <div><i>3. Single Logout Endpoint: <a
              class="moz-txt-link-freetext" href="https://identity"
              moz-do-not-send="true">https://identity</a>.</i><i>acme</i><i>.com/api/logout/</i><i>xxxxxxxxxx</i>
        </div>
        <i> 4. Login URL: </i><i><a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal.apps.us.bluescape.com_saml_single-5Fsign-5Fon_BluescapeInternalCorpSSO&d=DwMGaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=7jF46T-Hxl1VfpIxoSs-xpomxFwGgqYvcufOWXOxrnY&s=sXPamkw8jHfJ8MYfDnp150G9t7zQy1a08aplLBEE3r0&e="
            style="" id="LPlnk233021" moz-do-not-send="true"> </a></i><i><span
            style=""><a class="moz-txt-link-freetext"
              href="https://portal" moz-do-not-send="true">https://portal</a>.</span></i><i><span
            style="">acme.com/saml/single_sign_on/</span></i><i>xxxxxxxxxx
        </i></div>
      <br>
      Without the SP metadata, what options do I have to configure our
      IdP for this SP?<br>
    </blockquote>
    <p>1.  Point to your contract/RFP that specifically requires the
      vendor support SAML metadata.  (Unfortunately, this probably won't
      be an option for you This Time...)</p>
    <p>2.  Handcraft metadata for them, using the information provided. 
      Here is a starting point for you:
      <a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/CONCEPT/Metadata">https://wiki.shibboleth.net/confluence/display/CONCEPT/Metadata</a></p>
    <p>Since they can't be bothered to generate metadata for you, when
      they ask for your SSO URL and certificate, give them your metadata
      file and say "extract them yourself, chumps".</p>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>