<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<div class="moz-cite-prefix">I take the challenge to use IDP-proxing
in order to allow vendor SP (DocuSign) to take the IDP-proxy as
the only IDP registered, then that idp-proxy would request our
group of schools internal IDPs (don't know yet how it will pass
over each ones ..., I just test with one proxy and one IDP
"backend" ) . <br>
</div>
<div class="moz-cite-prefix">I followed
<a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP</a></div>
<div class="moz-cite-prefix">but I am wondering if I well understood
the roles of differrent parties in that doc <br>
</div>
<div class="moz-cite-prefix">
<ul>
<li><i>1) Original IdP EntityID: </i><i><code><a class="moz-txt-link-freetext" href="https://idp.example.ac.uk/entity">https://idp.example.ac.uk/entity</a>
# <br>
</code></i></li>
<li><i>2) Upstream IdP EntityID: </i><i><code><a class="moz-txt-link-freetext" href="https://upstream.idp/entity">https://upstream.idp/entity</a></code></i></li>
<li><i>3) Joining attribute (common to both services): </i><i><code>uid</code></i><i>
(unscoped username)</i></li>
</ul>
</div>
<div class="moz-cite-prefix">I took 1) as the IDP-Proxy (frontend to
all others current IDPs) and 2) as actual school's IDP, is this
correct interpretation ?</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">While testing on a local SP , I took
1) (IDP-proxy ) as the IDP to authenticate to, then expected to be
redirected to 2)</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">But IDP-proxy logs (in debug) shows an
INFO message about "No metadata in role ..." (in bold below) ,
that makes me wonder if I did correctly recorded the <code
class="xml spaces"></code><code class="xml plain"><</code><code
class="xml keyword">SPSSODescriptor </code>: <br>
</div>
<div class="moz-cite-prefix">element in the correct IDP metadata
(here I did it in 1) the proxy , not 2) !) <br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
21:54:01,286 - - DEBUG
[net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:369] -
Profile Action SelectAuthenticationFlow: Selecting inactive
authentication flow authn/SAML</i><i><br>
</i><i>2021-02-01 21:54:01,450 - - DEBUG
[net.shibboleth.idp.saml.session.impl.PrepareInboundMessageContext:143]
- Profile Action PrepareInboundMessageContext: Initialized
inbound context for message to
<a class="moz-txt-link-freetext" href="https://idpschool1.domain.fr/idp/shibboleth">https://idpschool1.domain.fr/idp/shibboleth</a></i><i><br>
</i><i>2021-02-01 21:54:01,457 - - INFO
[org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:167]
- Message Handler: </i><i><b>No metadata returned for
<a class="moz-txt-link-freetext" href="https://idpschool1.domain.fr/idp/shibboleth">https://idpschool1.domain.fr/idp/shibboleth</a> in role
{urn:oasis:names:tc:SAML:2.0:metadata}IDPSSODescriptor with
protocol urn:oasis:names:tc:SAML:2.0:protocol</b></i></font></div>
<div class="moz-cite-prefix"><font size="-1"><i><br>
</i></font></div>
<div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
21:54:01,467 - - WARN
[net.shibboleth.idp.profile.impl.SelectProfileConfiguration:118]
- <b>Profile Action SelectProfileConfiguration: Profile
<a class="moz-txt-link-freetext" href="http://shibboleth.net/ns/profiles/saml2/sso/browser">http://shibboleth.net/ns/profiles/saml2/sso/browser</a> is not
available for RP configuration
shibboleth.UnverifiedRelyingParty (RPID
<a class="moz-txt-link-freetext" href="https://idpschool1.domain.fr/idp/shibboleth">https://idpschool1.domain.fr/idp/shibboleth</a>)</b></i><i><br>
</i><i><br>
</i></font></div>
<div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
21:54:01,486 - - INFO
[net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:142] -
Profile Action SelectAuthenticationFlow:<b> Moving incomplete
flow authn/SAML to intermediate set</b></i><i><br>
</i></font></div>
<div class="moz-cite-prefix"><font size="-1"><i><br>
</i></font></div>
<div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
21:54:01,487 - - INFO
[net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] -
Profile Action SelectAuthenticationFlow: No potential flows
left to choose from, authentication failed</i><i><br>
</i><i><br>
</i></font></div>
<div class="moz-cite-prefix"><font size="-1"><i>2021-02-01
21:54:01,673 - - INFO [Shibboleth-Audit.SSO:282] -
2021-02-01T20:54:00.489203Z,2021-02-01T20:54:01.444210Z|2021-02-01T20:54:01.672917Z||<a class="moz-txt-link-freetext" href="https://testsp.domain.fr/sp||||||||false||Redirect|POST||Requester|urn:oasis:names:tc:SAML:2.0:status">https://testsp.domain.fr/sp||||||||false||Redirect|POST||Requester|urn:oasis:names:tc:SAML:2.0:status</a>:<b>AuthnFailed</b>|</i></font></div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">thanks to help me debug that touchy
configuration . <br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">Le 29/01/2021 à 17:23, Jehan PROCACCIA
a écrit :<br>
</div>
<blockquote type="cite"
cite="mid:856533502.7243575.1611937434405.JavaMail.zimbra@imtbs-tsp.eu">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<div style="font-family: arial, helvetica, sans-serif; font-size:
12pt; color: #000000">
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">Hello, <br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">I recently echange
here about my experiences on shibboleth IDP4 with DocuSign SP
(cf my howto: <a
href="https://www-public.imtbs-tsp.eu/~procacci/dok/doku.php?id=docpublic:systemes:shibboleth:docusign"
moz-do-not-send="true">https://www-public.imtbs-tsp.eu/~procacci/dok/doku.php?id=docpublic:systemes:shibboleth:docusign</a>)
<br data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">I noticed that
usually SP vendors don't provide Discocery Service/WAYF SP
initiated SSO (has we are used in academic/reserch ecosystem)
<br data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">so they ask us to
register as many IDP as we have universities/school in ou
group of federated IDPs . <br data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">I came accross
those pages: </div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><a class="moz-txt-link-freetext" href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP</a></div>
<div id="zimbraEditorContainer" style="font-family: arial,
helvetica, sans-serif; font-size: 12pt; color: #000000"
class="10"><a
href="https://spaces.at.internet2.edu/display/GS/SAMLIdPProxy"
moz-do-not-send="true">https://spaces.at.internet2.edu/display/GS/SAMLIdPProxy</a>
(quite old, I guess I should stick with the 1rst one ...) <br>
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">Do you think
that's a right choice to circumvent the lack of DS/WAYF , by
registering only One proxied IDP to the vendor SP and let that
proxied IDP do the job to delegate authN to our locals
federation end users IDPs ? </div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">Or would it be
better/simpler to present to the vendor SP only One IDP that
has access to each schools end users referentials (ldap) </div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><a
href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories"
moz-do-not-send="true">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories</a>
(I guess it works also in IDPv4) <br data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">or<br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><a class="moz-txt-link-freetext" href="https://github.com/ConsortiumGARR/idem-tutorials/blob/master/idem-fedops/HOWTO-Shibboleth/Solutions/HOWTO%20Configure%20a%20Shibboleth%20IdP%20v3.2.1%20to%20authenticate%20Users%20existing%20on%20different%20LDAP%20Servers.md">https://github.com/ConsortiumGARR/idem-tutorials/blob/master/idem-fedops/HOWTO-Shibboleth/Solutions/HOWTO%20Configure%20a%20Shibboleth%20IdP%20v3.2.1%20to%20authenticate%20Users%20existing%20on%20different%20LDAP%20Servers.md</a><br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">I'am at the
starting point to go into the direction of Proxy IDP or a
single IDP with multiple ldap directories, which would be a
better choice ? <br data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10"><br
data-mce-bogus="1">
</div>
<div style="font-family: arial, helvetica, sans-serif;
font-size: 12pt; color: #000000" class="10">thanks for you
advice . </div>
</div>
</blockquote>
<p><br>
</p>
</body>
</html>