<!DOCTYPE HTML><html>
<head>
<meta name="Generator" content="Amazon WorkMail v3.1.250.0">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>RE: Zoho Help SP claims no metadata</title>
</head>
<body>
<p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Baron,</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Typically on a query string, the AssertionConsumerService URL should be the shire parameter. The target should be the RelayState parameter. The entityID should be the providerId parameter.</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Remote login URL: <a href="https://your.idp/idp/profile/SAML2/SSO" _src="https://your.idp/idp/profile/SAML2/SSO">https://your.idp/idp/profile/SAML2/SSO</a></p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Remote logout URL: https://your.idp/idp/profile/Logout</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Password Reset URL: You'll know</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Key: Your IdP's public key, RSA</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">This is all as wonky as Scott says, yes.</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Take care,</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Nate.</p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px">--------</p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><img src="https://www.signet.id/wp-content/uploads/2019/08/signature-e1566142203123.png" /></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><font size="4">The Art of Access</font> <strong>®</strong></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><font size="2"><strong>Nate Klingenstein</strong> | Principal</font></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><font size="2"><a href="https://www.signet.id/">https://www.signet.id/</a> </font></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><blockquote style="border-left:2px solid #b0b0b7; margin-left:5px; margin-right:0px; padding-left:5px">-----Original message-----<br /><strong>From:</strong> Baron Fujimoto<br /><strong>Sent:</strong> Tuesday, June 16 2020, 5:37 pm<br /><strong>To:</strong> Shib Users<br /><strong>Subject:</strong> Re: Zoho Help SP claims no metadata<br /> <pre style="white-space:pre-wrap; word-wrap:break-word">At the risk of sounding more dense, I see in the documentation where the relay state maybe configured via the target parameter, but I'm missing specifically *where* these unsolicited SSO endpoints should be configured. The examples in the Shibboleth docs aren't clear to me on this.
<<a href="https://wiki.shibboleth.net/confluence/display/IDP30/UnsolicitedSSOConfiguration#UnsolicitedSSOConfiguration-RequestInterface">https://wiki.shibboleth.net/confluence/display/IDP30/UnsolicitedSSOConfiguration#UnsolicitedSSOConfiguration-RequestInterface</a>>
I notice now that this UnsolicitedSSSConfiguration page is a child page of RelyingPartyConfiguration, but I don't find any identifiable guidance there either.
<<a href="https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration</a>>
Nor on the page for the SAML 2 SSO configuration
<<a href="https://wiki.shibboleth.net/confluence/display/IDP30/SAML2SSOConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/SAML2SSOConfiguration</a>>
On Tue, Jun 16, 2020 at 11:10:37PM +0000, Cantor, Scott wrote:
>The metadata belonging to the SP is invariant with respect to where SSO begins. There is nothing about the IdP in an SP's metadata regardless, and the SP's metadata would look essentially identical whether it supported requests or not.
>
>IdP initiated SSO is nothing more than a proprietary URL to tell the IdP to generate a response targeted to an SP. It's an unsigned request with limited features. There's nothing about it that involves metadata that isn't necessary in a normal case, which is, I guess, a good thing.
>
>RelayState is another matter. There should never be RelayState unless it comes from an SP and when it's imposed in such a case, the SP is doubly broken by forcing its local requirements on the IdP without simply implementing the standard to begin with. If they want RelayState, then they should issue requests containing it.
>
>Like most incorrect ways of using SAML, it's still supported; a target parameter to the IdP will produce a RelayState value matching it.
>
>-- Scott
>
>
>--
>For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">https://wiki.shibboleth.net/confluence/x/coFAAg</a>
>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a>
--
UH Information Technology Services : Identity & Access Mgmt, Middleware
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum
--
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">https://wiki.shibboleth.net/confluence/x/coFAAg</a>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a>
</pre></blockquote>
</body>
</html>