<div dir="ltr"><div dir="ltr">Hi Don,<input name="virtru-metadata" type="hidden" value="{"email-policy":{"state":"closed","expirationUnit":"days","disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"persistentProtection":false,"expandedWatermarking":false,"expires":false,"isManaged":false},"attachments":{},"compose-id":"16","compose-window":{"secure":false}}"><div><br></div><div>We set up our Zoom integration via InCommon three years ago.  We are using email, but not in the nameID -- just in a regular attribute.</div><div>The InCommon setup went very smoothly, and it has been working well ever since.</div><div><br></div><div>We also pass an entitlement string, the value of which we assign according to Grouper groups, that controls access to different account types.</div><div><br></div><div>Joanne</div><div><br></div><div>---</div><div><br></div><div><span style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif">Joanne Schwendner</span><br style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif"><span style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif">Senior Developer - </span><font color="#888888">Web, Integration, & Identity Services</font><br style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif"><span style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif">Brown University</span>  <br></div><div><br></div></div><br><div class="gmail_quote" style=""><div dir="ltr" class="gmail_attr">On Mon, Aug 24, 2020 at 3:05 PM Donald Lohr <<a href="mailto:lohrda@jmu.edu">lohrda@jmu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
  
    
  
  <div>
    Thanks, this has been very helpful.<br>
    <br>
    Does anyone have a functioning Shibboleth IdP configuration via
    InCommon?<br>
    <br>
    The reason I ask, is that another school told us:<br>
    <br>
    <div title="Page 1">
      <div>
        <div> <i><span style="font-size:12pt">Zoom is
              an InCommon member and we first attempted to configure
              with InCommon. However,
              we had some challenges with the way they signed assertions
              and logout. So, we decided we
              should do a manual configuration of SSO instead.
            </span></i><br>
        </div>
      </div>
    </div>
    <br>
    But I believe they've been a Zoom customer for a few years.<br>
    <br>
    Thanks,<br>
    Don<br>
    <br>
    <br>
    <div>On 8/21/20 10:41 PM, Lohr, Donald A -
      lohrda wrote:<br>
    </div>
    <blockquote type="cite">
      
      <div>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt">Referring
            to this URL:</span></p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt"></span><br>
        </p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__support.zoom.us_hc_en-2Dus_articles_201363003-2DGetting-2Dstarted-2Dwith-2DSSO&d=DwMGaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=fLnm-WN9U4d94T42-8yB77D1UNg2gyNoFMXbDF8Oh9w&s=apt4aG3d0K1Wv8QERvPkmi6ynRplZudGFD6sPI3ZN8c&e=" target="_blank">https://support.zoom.us/hc/en-us/articles/201363003-Getting-started-with-SSO</a></span></p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt"></span><br>
        </p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt">...it
            states the following:</span></p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt"></span><br>
        </p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt">First,
            configure your IdP to send us the following</span></p>
        <ul>
          <li>
            <span style="font-family:Menlo-Regular;font-size:10pt"></span><span style="font-family:".SFUIText";font-size:17pt">Any
              unique identifier linked to nameID such as
              eduPersonTargetedID, persistentID, or mail</span>
          </li>
          <li>
            <span style="font-family:Menlo-Regular;font-size:10pt"></span><span style="font-family:".SFUIText";font-size:17pt">(Optional)
              Accepted attributes are email (urn:oid:0.9.2342.19200300.
              100.1.3), sn (urn:oid:2.5.4.4), and givenName
              (urn:oid:2.5.4.42).</span>
          </li>
        </ul>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt"></span><br>
        </p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt">Our
            plan would be to configure Shibboleth to set the nameID for
            Zoom to not be a user's email address. We want to use a
            better unique & never changing attribute, the user's
            eduPersonUniqueId attribute value. We will also send Zoom a
            user's mail, givenname and sn attribute values.</span></p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt"></span><br>
        </p>
        <p>
          <span style="font-family:".SFUIText";font-size:17pt">Is
            anyone's Shibboleth configuration for Zoom using something
            other than email as the nameID value?  If so have you
            encountered any issues with nameID not set as a users email
            value? Especially with SSO login, the emailing of or
            accepting invitations or using the Canvas LTI Pro component.</span></p>
        <br>
        <span style="background-color:rgba(255,255,255,0)">-- <br>
          D o n a l d   L o h r<br>
          I n f o r m a t i o n   S y s t e m s<br>
          J a m e s   M a d i s o n   U n i v e r s i t y<br>
          5 4 0 . 5 6 8 . 3 7 3 0</span></div>
      <br>
      <fieldset></fieldset>
    </blockquote>
    <br>
    <pre cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div></div>