<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">I take the challenge to use IDP-proxing
      in order to allow vendor SP (DocuSign) to take the IDP-proxy as
      the only IDP registered, then that idp-proxy would request our
      group of schools internal IDPs  (don't know yet how it will pass
      over each ones ..., I just test with one proxy and one IDP
      "backend" ) .    <br>
    </div>
    <div class="moz-cite-prefix">I followed
<a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP</a></div>
    <div class="moz-cite-prefix">but I am wondering if I well understood
      the roles of differrent parties in that doc <br>
    </div>
    <div class="moz-cite-prefix">
      <ul>
        <li><i>1) Original IdP EntityID: </i><i><code><a class="moz-txt-link-freetext" href="https://idp.example.ac.uk/entity">https://idp.example.ac.uk/entity</a>
              # <br>
            </code></i></li>
        <li><i>2) Upstream IdP EntityID: </i><i><code><a class="moz-txt-link-freetext" href="https://upstream.idp/entity">https://upstream.idp/entity</a></code></i></li>
        <li><i>3) Joining attribute (common to both services): </i><i><code>uid</code></i><i>
            (unscoped username)</i></li>
      </ul>
    </div>
    <div class="moz-cite-prefix">I took 1) as the IDP-Proxy (frontend to
      all others current IDPs) and 2) as actual school's IDP, is this
      correct interpretation ?</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">While testing on a local SP  , I took
      1) (IDP-proxy ) as the IDP to authenticate to, then expected to be
      redirected to 2)</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">But IDP-proxy logs (in debug) shows an
      INFO message about "No metadata in role ..." (in bold below) ,
      that makes me wonder if I did correctly recorded the  <code
        class="xml spaces"></code><code class="xml plain"><</code><code
        class="xml keyword">SPSSODescriptor </code>:   <br>
    </div>
    <div class="moz-cite-prefix">element in the correct IDP metadata
      (here I did it in 1) the proxy , not 2) !) <br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
          21:54:01,286 - - DEBUG
          [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:369] -
          Profile Action SelectAuthenticationFlow: Selecting inactive
          authentication flow authn/SAML</i><i><br>
        </i><i>2021-02-01 21:54:01,450 - - DEBUG
          [net.shibboleth.idp.saml.session.impl.PrepareInboundMessageContext:143]
          - Profile Action PrepareInboundMessageContext: Initialized
          inbound context for message to
          <a class="moz-txt-link-freetext" href="https://idpschool1.domain.fr/idp/shibboleth">https://idpschool1.domain.fr/idp/shibboleth</a></i><i><br>
        </i><i>2021-02-01 21:54:01,457 -  - INFO
          [org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:167]
          - Message Handler:  </i><i><b>No metadata returned for
            <a class="moz-txt-link-freetext" href="https://idpschool1.domain.fr/idp/shibboleth">https://idpschool1.domain.fr/idp/shibboleth</a> in role
            {urn:oasis:names:tc:SAML:2.0:metadata}IDPSSODescriptor with
            protocol urn:oasis:names:tc:SAML:2.0:protocol</b></i></font></div>
    <div class="moz-cite-prefix"><font size="-1"><i><br>
        </i></font></div>
    <div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
          21:54:01,467 -  - WARN
          [net.shibboleth.idp.profile.impl.SelectProfileConfiguration:118]
          - <b>Profile Action SelectProfileConfiguration: Profile
            <a class="moz-txt-link-freetext" href="http://shibboleth.net/ns/profiles/saml2/sso/browser">http://shibboleth.net/ns/profiles/saml2/sso/browser</a> is not
            available for RP configuration
            shibboleth.UnverifiedRelyingParty (RPID
            <a class="moz-txt-link-freetext" href="https://idpschool1.domain.fr/idp/shibboleth">https://idpschool1.domain.fr/idp/shibboleth</a>)</b></i><i><br>
        </i><i><br>
        </i></font></div>
    <div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
          21:54:01,486 - - INFO
          [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:142] -
          Profile Action SelectAuthenticationFlow:<b> Moving incomplete
            flow authn/SAML to intermediate set</b></i><i><br>
        </i></font></div>
    <div class="moz-cite-prefix"><font size="-1"><i><br>
        </i></font></div>
    <div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
          21:54:01,487 - - INFO
          [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] -
          Profile Action SelectAuthenticationFlow: No potential flows
          left to choose from, authentication failed</i><i><br>
        </i><i><br>
        </i></font></div>
    <div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
          21:54:01,673 -  - INFO [Shibboleth-Audit.SSO:282] -
2021-02-01T20:54:00.489203Z,2021-02-01T20:54:01.444210Z|2021-02-01T20:54:01.672917Z||<a class="moz-txt-link-freetext" href="https://testsp.domain.fr/sp||||||||false||Redirect|POST||Requester|urn:oasis:names:tc:SAML:2.0:status">https://testsp.domain.fr/sp||||||||false||Redirect|POST||Requester|urn:oasis:names:tc:SAML:2.0:status</a>:<b>AuthnFailed</b>|</i></font></div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">thanks to help me debug that touchy
      configuration . <br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">Le 29/01/2021 à 17:23, Jehan PROCACCIA
      a écrit :<br>
    </div>
    <blockquote type="cite"
      cite="mid:856533502.7243575.1611937434405.JavaMail.zimbra@imtbs-tsp.eu">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div style="font-family: arial, helvetica, sans-serif; font-size:
        12pt; color: #000000">
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">Hello, <br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">I recently echange
          here about my experiences on shibboleth IDP4 with DocuSign SP
          (cf my howto: <a
href="https://www-public.imtbs-tsp.eu/~procacci/dok/doku.php?id=docpublic:systemes:shibboleth:docusign"
            moz-do-not-send="true">https://www-public.imtbs-tsp.eu/~procacci/dok/doku.php?id=docpublic:systemes:shibboleth:docusign</a>)
          <br data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">I noticed that
          usually SP vendors don't provide Discocery Service/WAYF SP
          initiated SSO  (has we are used in academic/reserch ecosystem)
          <br data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">so they ask us to
          register as many IDP as we have universities/school in ou
          group of federated IDPs . <br data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">I came accross
          those pages: </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP</a></div>
        <div id="zimbraEditorContainer" style="font-family: arial,
          helvetica, sans-serif; font-size: 12pt; color: #000000"
          class="10"><a
            href="https://spaces.at.internet2.edu/display/GS/SAMLIdPProxy"
            moz-do-not-send="true">https://spaces.at.internet2.edu/display/GS/SAMLIdPProxy</a>
          (quite old, I guess I should stick with the 1rst one ...) <br>
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">Do you think
          that's a right choice to circumvent the lack of DS/WAYF , by
          registering only One proxied IDP to the vendor SP and let that
          proxied IDP do the job to delegate authN to our locals
          federation end users IDPs ? </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">Or would it be
          better/simpler to present to the vendor SP only One IDP that
          has access to each schools end users referentials (ldap) </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><a
href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories"
            moz-do-not-send="true">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories</a>
          (I guess it works also in IDPv4) <br data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">or<br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><a class="moz-txt-link-freetext" href="https://github.com/ConsortiumGARR/idem-tutorials/blob/master/idem-fedops/HOWTO-Shibboleth/Solutions/HOWTO%20Configure%20a%20Shibboleth%20IdP%20v3.2.1%20to%20authenticate%20Users%20existing%20on%20different%20LDAP%20Servers.md">https://github.com/ConsortiumGARR/idem-tutorials/blob/master/idem-fedops/HOWTO-Shibboleth/Solutions/HOWTO%20Configure%20a%20Shibboleth%20IdP%20v3.2.1%20to%20authenticate%20Users%20existing%20on%20different%20LDAP%20Servers.md</a><br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">I'am at the
          starting point to go into the direction of Proxy IDP or a
          single IDP with multiple ldap directories, which would be a
          better choice ? <br data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10"><br
            data-mce-bogus="1">
        </div>
        <div style="font-family: arial, helvetica, sans-serif;
          font-size: 12pt; color: #000000" class="10">thanks for you
          advice . </div>
      </div>
    </blockquote>
    <p><br>
    </p>
  </body>
</html>