<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    1) The vendor reported back that they do not believe that our
    entityID that's a urn value is the issue.<br>
    <br>
    2) In our production Shibboleth metadata are four
    SingleSignOnService Binding elements:<br>
    <br>
    <tt><tt><SingleSignOnService
        Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
        Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/shibboleth-idp/SSO">"https://itfederation.jmu.edu/shibboleth-idp/SSO"</a>/></tt><br>
      <br>
      <SingleSignOnService
      Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
      Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/idp/profile/SAML2/POST/SSO">"https://itfederation.jmu.edu/idp/profile/SAML2/POST/SSO"</a>/></tt><tt><br>
    </tt><tt><br>
      <SingleSignOnService
      Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/idp/profile/SAML2/POST-SimpleSign/SSO">"https://itfederation.jmu.edu/idp/profile/SAML2/POST-SimpleSign/SSO"</a>/></tt><tt><br>
    </tt><tt><br>
      <SingleSignOnService
      Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
      Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SSO">"https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SSO"</a>/</tt><tt>></tt><br>
    <br>
    The vendor is asking why does our production Shibboleth IdP metadata
    have the following Binding:<br>
    <tt><br>
    </tt><tt><SingleSignOnService
      Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
      Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/shibboleth-idp/SSO">"https://itfederation.jmu.edu/shibboleth-idp/SSO"</a>/></tt><br>
    <br>
    Putting that Location url in a browser goes to an error:<br>
    <br>
    <table width="368" height="31" cellspacing="2" cellpadding="2"
      border="1">
      <tbody>
        <tr>
          <td valign="top"><b>HTTP ERROR: 404</b><b><br>
            </b><b>
            </b><br>
            Problem accessing /shibboleth-idp/SSO. Reason:
            <br>
            <br>
            Not Found</td>
        </tr>
      </tbody>
    </table>
    <br>
    Putting the other three Location urls in a browser returns the
    following error:<br>
    <br>
    <table width="369" height="31" cellspacing="2" cellpadding="2"
      border="1">
      <tbody>
        <tr>
          <td valign="top"><b>Web Login Service - Stale Request</b><br>
          </td>
        </tr>
      </tbody>
    </table>
    <br>
    <br>
    3) When I originally configured this SP against our non-production
    Shibboleth IdP, its metadata does not have this url <br>
    <br>
    <tt><SingleSignOnService
      Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
      Location=............</tt><br>
    <br>
    It only has the last three listed above.<br>
    <br>
    4) The vendor is also about the HTTP-POST and HTTP-Redirect binding,
    stating:<br>
    <br>
    <i>For other IdPs we've worked with, those two bindings (HTTP-POST
      and HTTP-Redirect) are the same endpoint but you currently have
      different endpoints for different bindings. We would like to know
      which endpoint works on the current production IdP.</i><i><br>
    </i><br>
    <br>
    Thanks,<br>
    Don<br>
    <br>
    <div class="moz-cite-prefix">On 5/26/20 6:45 PM, Lohr, Donald wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:27f1be91-048f-b348-5216-63f6e2816ab7@jmu.edu">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      I've another odd one.  <br>
      <br>
      Working with a vendor to configure their SP.  They only
      support/certify the following IdP's (Okta, Azure Active Directory,
      Ping Federate, F5 and onelogin) and not Shibboleth.<br>
      <br>
      We have a non-production Shibboleth IdP server and I was able to
      get a working configuration to login via this non-production
      Shibboleth IdP and a test instance of their application, using a
      "IdP Initiated" model.<br>
      <br>
      On our non-production Shibboleth IdP it has a <b>https://</b> url
      style entityID value that we made up when we build this server. 
      On our production Shibboleth IdP, it has a <b>urn:mace:incommon:</b>
      style entityID value.<br>
      <br>
      Needless to say this vendor is not a InCommon member.<br>
      <br>
      I do not even know how to answer their questions as to why our
      production Shibboleth IdP has a urn: vs a https: style entityID
      value.  I have a whole bunch of other questions running in my mind
      I do not even know how to ask.<br>
      <br>
      Sorry,<br>
      Don<br>
      <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>