<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<div class="moz-cite-prefix">On 2/11/2020 8:32 AM, Lohr, Donald
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:38c6ae7a-8145-0273-afa6-755dcea0c671@jmu.edu">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
We have a new SP to configure and the vendor is not an InCommon
member and states the following:<br>
<br>
<i>We support both Identify Provider or Service Provider initiated
methods, as both are equally viable for us. We never provide the
metadata file or URL. We only provide links such as the ACS URL
or Entity ID. We also produce the login and logout URL but some
IDPs don't require or use it. This is all unrelated to whether
or not it is SP or IDP initiated. </i>
<div style="font-size: 12pt; color: rgb(0, 0, 0);
background-color: rgb(255, 255, 255);"> <i><br>
</i> </div>
<i> </i>
<div style="font-size: 12pt; color: rgb(0, 0, 0);
background-color: rgb(255, 255, 255);"><i> Example:</i></div>
<i> </i>
<div style="font-size: 12pt; color: rgb(0, 0, 0);
background-color: rgb(255, 255, 255);"><i> 1. Entity ID: <a
class="moz-txt-link-freetext"
href="https://portal.acme.com/saml/metadata/xxxxxxxxxx"
moz-do-not-send="true">https://portal.acme.com/saml/metadata/xxxxxxxxxx</a></i><i><br>
</i>
<div><i>2. ACS URL: <a class="moz-txt-link-freetext"
href="https://identity" moz-do-not-send="true">https://identity</a></i><i>.acme</i><i>.com/api/authenticate/</i><i>xxxxxxxxxx</i>
</div>
<div><i>3. Single Logout Endpoint: <a
class="moz-txt-link-freetext" href="https://identity"
moz-do-not-send="true">https://identity</a>.</i><i>acme</i><i>.com/api/logout/</i><i>xxxxxxxxxx</i>
</div>
<i> 4. Login URL: </i><i><a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal.apps.us.bluescape.com_saml_single-5Fsign-5Fon_BluescapeInternalCorpSSO&d=DwMGaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=7jF46T-Hxl1VfpIxoSs-xpomxFwGgqYvcufOWXOxrnY&s=sXPamkw8jHfJ8MYfDnp150G9t7zQy1a08aplLBEE3r0&e="
style="" id="LPlnk233021" moz-do-not-send="true"> </a></i><i><span
style=""><a class="moz-txt-link-freetext"
href="https://portal" moz-do-not-send="true">https://portal</a>.</span></i><i><span
style="">acme.com/saml/single_sign_on/</span></i><i>xxxxxxxxxx
</i></div>
<br>
Without the SP metadata, what options do I have to configure our
IdP for this SP?<br>
</blockquote>
<p>1. Point to your contract/RFP that specifically requires the
vendor support SAML metadata. (Unfortunately, this probably won't
be an option for you This Time...)</p>
<p>2. Handcraft metadata for them, using the information provided.
Here is a starting point for you:
<a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/CONCEPT/Metadata">https://wiki.shibboleth.net/confluence/display/CONCEPT/Metadata</a></p>
<p>Since they can't be bothered to generate metadata for you, when
they ask for your SSO URL and certificate, give them your metadata
file and say "extract them yourself, chumps".</p>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a> %%
%% OIT - Identity Management %% <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a> %%
%% University of Minnesota %% +1 (612) 625-1809 %%
</pre>
</body>
</html>