<div dir="ltr">We've done a three Cloudflare Access integrations so far.<div><br></div><div>The odd integrations occasionally run together, but it could be that CloudFlare was one that used what I considered backward terminology for the IdP and SP entity ID's. (I know I had one of those in recent months.) I don't actually have access to our CF admin consoles, so I can't look for sure. But I do know that the process only took 10 minutes or so to get going.</div><div><br></div><div>I imagine we manually configured it. I can get someone to give me the config details, if that would be helpful.</div><div><br></div><div>(My biggest integration problem so far has been that one of my colleagues likes to leave the validUntil attributes in their metadata, and I've been contacted when the CF Access logins suddenly fail.)</div><div><br></div><div>Greg</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Oct 23, 2020 at 9:00 AM Darren Boss <<a href="mailto:darren.boss@computecanada.ca">darren.boss@computecanada.ca</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Cloudflare access is their VPN alternative that requires<br>
authentication before the request gets proxied over the CloudFlare<br>
network.<br>
<br>
<a href="https://www.cloudflare.com/teams/access/" rel="noreferrer" target="_blank">https://www.cloudflare.com/teams/access/</a><br>
<br>
I've tried integration with both SAML (version 4.0.1) and OIDC with<br>
the 2.0.0 extension and can't get either to work. They allow for<br>
upload of your IdP metadata but when I do that it chooses the<br>
HTTP-POST url but does a get request. After loading the metadata or if<br>
you ignore the metadata upload feature you can just fill in the fields<br>
directly so I switch to the redirect url, waited for the change to<br>
propagate and then I got an error because the entityid was set to the<br>
entityid of the IdP and not the SP? Very odd.<br>
<br>
I gave up and tried OIDC but my email claim is not available after<br>
auth. I watched the logs on the IdP from a known working OIDC client<br>
and it looks like Cloudflare is not using the userinfo endpoint. They<br>
only have three fields when entering OIDC info, auth, token and<br>
certificate and they don't seem to support discovery. Only the sub<br>
claim was available to Cloudflare but I did get release consent for<br>
email. I have "openid email profile" configured in the scope in the<br>
cloudflare metadata.<br>
<br>
I can provide more information (logs and configuration) but I was<br>
hoping that maybe someone has done this integration and knows how to<br>
get this working with Shibboleth using either SAML or OIDC.<br>
-- <br>
Darren Boss<br>
Senior Programmer/Analyst<br>
Programmeur-analyste principal<br>
<a href="mailto:darren.boss@computecanada.ca" target="_blank">darren.boss@computecanada.ca</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>