<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
Thanks. That url helped me construct a basic SP metadata file and
auth now works.<br>
<br>
Don<br>
<br>
<div class="moz-cite-prefix">On 2/11/20 10:06 AM, Christopher
Bongaarts wrote:<br>
</div>
<blockquote type="cite"
cite="mid:75fd8cd0-0421-1872-4e31-fa3d2c597ba4@umn.edu">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<div class="moz-cite-prefix">On 2/11/2020 8:32 AM, Lohr, Donald
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:38c6ae7a-8145-0273-afa6-755dcea0c671@jmu.edu"> We have
a new SP to configure and the vendor is not an InCommon member
and states the following:<br>
<br>
<i>We support both Identify Provider or Service Provider
initiated methods, as both are equally viable for us. We never
provide the metadata file or URL. We only provide links such
as the ACS URL or Entity ID. We also produce the login and
logout URL but some IDPs don't require or use it. This is all
unrelated to whether or not it is SP or IDP initiated. </i>
<div style="font-size: 12pt; color: rgb(0, 0, 0);
background-color: rgb(255, 255, 255);"> <i><br>
</i> </div>
<i> </i>
<div style="font-size: 12pt; color: rgb(0, 0, 0);
background-color: rgb(255, 255, 255);"><i> Example:</i></div>
<i> </i>
<div style="font-size: 12pt; color: rgb(0, 0, 0);
background-color: rgb(255, 255, 255);"><i> 1. Entity ID: <a
class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal.acme.com_saml_metadata_xxxxxxxxxx&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=m4HaE7YAZ1TMNLlIZ9qV3PnOPlvzx08tG8Y6bvaVix8&e="
moz-do-not-send="true">https://portal.acme.com/saml/metadata/xxxxxxxxxx</a></i><i><br>
</i>
<div><i>2. ACS URL: <a class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__identity&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=ph8AnZlGnp8FNj-HQmuOYSXx6g72fszUkxjcJCf7oag&e="
moz-do-not-send="true">https://identity</a></i><i>.acme</i><i>.com/api/authenticate/</i><i>xxxxxxxxxx</i>
</div>
<div><i>3. Single Logout Endpoint: <a
class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__identity&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=ph8AnZlGnp8FNj-HQmuOYSXx6g72fszUkxjcJCf7oag&e="
moz-do-not-send="true">https://identity</a>.</i><i>acme</i><i>.com/api/logout/</i><i>xxxxxxxxxx</i>
</div>
<i> 4. Login URL: </i><i><a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal.apps.us.bluescape.com_saml_single-5Fsign-5Fon_BluescapeInternalCorpSSO&d=DwMGaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=7jF46T-Hxl1VfpIxoSs-xpomxFwGgqYvcufOWXOxrnY&s=sXPamkw8jHfJ8MYfDnp150G9t7zQy1a08aplLBEE3r0&e="
style="" id="LPlnk233021" moz-do-not-send="true"> </a></i><i><span
style=""><a class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__portal&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=iuipY1j9zWL0y-aodhaYtQc557aoNIH9xiqjnULsdJg&e="
moz-do-not-send="true">https://portal</a>.</span></i><i><span
style="">acme.com/saml/single_sign_on/</span></i><i>xxxxxxxxxx
</i></div>
<br>
Without the SP metadata, what options do I have to configure our
IdP for this SP?<br>
</blockquote>
<p>1. Point to your contract/RFP that specifically requires the
vendor support SAML metadata. (Unfortunately, this probably
won't be an option for you This Time...)</p>
<p>2. Handcraft metadata for them, using the information
provided. Here is a starting point for you: <a
class="moz-txt-link-freetext"
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_CONCEPT_Metadata&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=H-6VSY3b20SXPwWv72DFpyjmD-FgICCKyyYLDBmRBN4&e="
moz-do-not-send="true">https://wiki.shibboleth.net/confluence/display/CONCEPT/Metadata</a></p>
<p>Since they can't be bothered to generate metadata for you, when
they ask for your SSO URL and certificate, give them your
metadata file and say "extract them yourself, chumps".</p>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu" moz-do-not-send="true">cab@umn.edu</a> %%
%% OIT - Identity Management %% <a class="moz-txt-link-freetext" href="https://urldefense.proofpoint.com/v2/url?u=http-3A__umn.edu_-7Ecab&d=DwMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=09v9FRv5Bnb8f6FgCub-1yHXtNJimdxXDp298e8ipjI&s=MOFZof_Mpbv7e6ycCx3r4b0AUVklwfgXPW6N5eyM-ns&e=" moz-do-not-send="true">http://umn.edu/~cab</a> %%
%% University of Minnesota %% +1 (612) 625-1809 %%
</pre>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>