<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    Thanks.  That url helped me construct a basic SP metadata file and
    auth now works.<br>
    <br>
    Don<br>
    <br>
    <div class="moz-cite-prefix">On 2/11/20 10:06 AM, Christopher
      Bongaarts wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:75fd8cd0-0421-1872-4e31-fa3d2c597ba4@umn.edu">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <div class="moz-cite-prefix">On 2/11/2020 8:32 AM, Lohr, Donald
        wrote:<br>
      </div>
      <blockquote type="cite"
        cite="mid:38c6ae7a-8145-0273-afa6-755dcea0c671@jmu.edu"> We have
        a new SP to configure and the vendor is not an InCommon member
        and states the following:<br>
        <br>
        <i>We support both Identify Provider or Service Provider
          initiated methods, as both are equally viable for us. We never
          provide the metadata file or URL. We only provide links such
          as the ACS URL or Entity ID. We also produce the login and
          logout URL but some IDPs don't require or use it. This is all
          unrelated to whether or not it is SP or IDP initiated.  </i>
        <div style="font-size: 12pt; color: rgb(0, 0, 0);
          background-color: rgb(255, 255, 255);"> <i><br>
          </i> </div>
        <i> </i>
        <div style="font-size: 12pt; color: rgb(0, 0, 0);
          background-color: rgb(255, 255, 255);"><i> Example:</i></div>
        <i> </i>
        <div style="font-size: 12pt; color: rgb(0, 0, 0);
          background-color: rgb(255, 255, 255);"><i> 1. Entity ID: <a
              class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal.acme.com_saml_metadata_xxxxxxxxxx&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=m4HaE7YAZ1TMNLlIZ9qV3PnOPlvzx08tG8Y6bvaVix8&e="
              moz-do-not-send="true">https://portal.acme.com/saml/metadata/xxxxxxxxxx</a></i><i><br>
          </i>
          <div><i>2. ACS URL: <a class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__identity&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=ph8AnZlGnp8FNj-HQmuOYSXx6g72fszUkxjcJCf7oag&e="
                moz-do-not-send="true">https://identity</a></i><i>.acme</i><i>.com/api/authenticate/</i><i>xxxxxxxxxx</i>
          </div>
          <div><i>3. Single Logout Endpoint: <a
                class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__identity&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=ph8AnZlGnp8FNj-HQmuOYSXx6g72fszUkxjcJCf7oag&e="
                moz-do-not-send="true">https://identity</a>.</i><i>acme</i><i>.com/api/logout/</i><i>xxxxxxxxxx</i>
          </div>
          <i> 4. Login URL: </i><i><a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal.apps.us.bluescape.com_saml_single-5Fsign-5Fon_BluescapeInternalCorpSSO&d=DwMGaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=7jF46T-Hxl1VfpIxoSs-xpomxFwGgqYvcufOWXOxrnY&s=sXPamkw8jHfJ8MYfDnp150G9t7zQy1a08aplLBEE3r0&e="
              style="" id="LPlnk233021" moz-do-not-send="true"> </a></i><i><span
              style=""><a class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=iuipY1j9zWL0y-aodhaYtQc557aoNIH9xiqjnULsdJg&e="
                moz-do-not-send="true">https://portal</a>.</span></i><i><span
              style="">acme.com/saml/single_sign_on/</span></i><i>xxxxxxxxxx
          </i></div>
        <br>
        Without the SP metadata, what options do I have to configure our
        IdP for this SP?<br>
      </blockquote>
      <p>1.  Point to your contract/RFP that specifically requires the
        vendor support SAML metadata.  (Unfortunately, this probably
        won't be an option for you This Time...)</p>
      <p>2.  Handcraft metadata for them, using the information
        provided.  Here is a starting point for you: <a
          class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_CONCEPT_Metadata&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=H-6VSY3b20SXPwWv72DFpyjmD-FgICCKyyYLDBmRBN4&e="
          moz-do-not-send="true">https://wiki.shibboleth.net/confluence/display/CONCEPT/Metadata</a></p>
      <p>Since they can't be bothered to generate metadata for you, when
        they ask for your SSO URL and certificate, give them your
        metadata file and say "extract them yourself, chumps".</p>
      <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu" moz-do-not-send="true">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="https://urldefense.proofpoint.com/v2/url?u=http-3A__umn.edu_-7Ecab&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=MOFZof_Mpbv7e6ycCx3r4b0AUVklwfgXPW6N5eyM-ns&e=" moz-do-not-send="true">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
 I n f o r m a t i o n   S y s t e m s
 J a m e s   M a d i s o n   U n i v e r s i t y
 5 4 0 . 5 6 8 . 3 7 3 0

</pre>
  </body>
</html>