<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
1) The vendor reported back that they do not believe that our
entityID that's a urn value is the issue.<br>
<br>
2) In our production Shibboleth metadata are four
SingleSignOnService Binding elements:<br>
<br>
<tt><tt><SingleSignOnService
Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/shibboleth-idp/SSO">"https://itfederation.jmu.edu/shibboleth-idp/SSO"</a>/></tt><br>
<br>
<SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/idp/profile/SAML2/POST/SSO">"https://itfederation.jmu.edu/idp/profile/SAML2/POST/SSO"</a>/></tt><tt><br>
</tt><tt><br>
<SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/idp/profile/SAML2/POST-SimpleSign/SSO">"https://itfederation.jmu.edu/idp/profile/SAML2/POST-SimpleSign/SSO"</a>/></tt><tt><br>
</tt><tt><br>
<SingleSignOnService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SSO">"https://itfederation.jmu.edu/idp/profile/SAML2/Redirect/SSO"</a>/</tt><tt>></tt><br>
<br>
The vendor is asking why does our production Shibboleth IdP metadata
have the following Binding:<br>
<tt><br>
</tt><tt><SingleSignOnService
Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
Location=<a class="moz-txt-link-rfc2396E" href="https://itfederation.jmu.edu/shibboleth-idp/SSO">"https://itfederation.jmu.edu/shibboleth-idp/SSO"</a>/></tt><br>
<br>
Putting that Location url in a browser goes to an error:<br>
<br>
<table width="368" height="31" cellspacing="2" cellpadding="2"
border="1">
<tbody>
<tr>
<td valign="top"><b>HTTP ERROR: 404</b><b><br>
</b><b>
</b><br>
Problem accessing /shibboleth-idp/SSO. Reason:
<br>
<br>
Not Found</td>
</tr>
</tbody>
</table>
<br>
Putting the other three Location urls in a browser returns the
following error:<br>
<br>
<table width="369" height="31" cellspacing="2" cellpadding="2"
border="1">
<tbody>
<tr>
<td valign="top"><b>Web Login Service - Stale Request</b><br>
</td>
</tr>
</tbody>
</table>
<br>
<br>
3) When I originally configured this SP against our non-production
Shibboleth IdP, its metadata does not have this url <br>
<br>
<tt><SingleSignOnService
Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
Location=............</tt><br>
<br>
It only has the last three listed above.<br>
<br>
4) The vendor is also about the HTTP-POST and HTTP-Redirect binding,
stating:<br>
<br>
<i>For other IdPs we've worked with, those two bindings (HTTP-POST
and HTTP-Redirect) are the same endpoint but you currently have
different endpoints for different bindings. We would like to know
which endpoint works on the current production IdP.</i><i><br>
</i><br>
<br>
Thanks,<br>
Don<br>
<br>
<div class="moz-cite-prefix">On 5/26/20 6:45 PM, Lohr, Donald wrote:<br>
</div>
<blockquote type="cite"
cite="mid:27f1be91-048f-b348-5216-63f6e2816ab7@jmu.edu">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
I've another odd one. <br>
<br>
Working with a vendor to configure their SP. They only
support/certify the following IdP's (Okta, Azure Active Directory,
Ping Federate, F5 and onelogin) and not Shibboleth.<br>
<br>
We have a non-production Shibboleth IdP server and I was able to
get a working configuration to login via this non-production
Shibboleth IdP and a test instance of their application, using a
"IdP Initiated" model.<br>
<br>
On our non-production Shibboleth IdP it has a <b>https://</b> url
style entityID value that we made up when we build this server.
On our production Shibboleth IdP, it has a <b>urn:mace:incommon:</b>
style entityID value.<br>
<br>
Needless to say this vendor is not a InCommon member.<br>
<br>
I do not even know how to answer their questions as to why our
production Shibboleth IdP has a urn: vs a https: style entityID
value. I have a whole bunch of other questions running in my mind
I do not even know how to ask.<br>
<br>
Sorry,<br>
Don<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>