<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thank you, Peter, for the detailed reply. I will explore them.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Initially, when we set up the federated access, we were using the on-premises AD for authentication, and everything worked fine with all the publishers' platforms. Recently, we had to switch to the Azure AD for authentication, and since then, we are having
an issue with some of the publishers.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
- Francis</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> 20 February 2021 19:23<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Access issue with some publisher platforms</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">External Email<br>
<br>
<br>
* Francis Jayakanth via users <users@shibboleth.net> [2021-02-20 14:39]:<br>
> HI, we are using Shibboleth IdP 4.0.1 along with Azure AD tenant<br>
<br>
FTR, I don't know what that means or how the "Azure AD tenant" part is<br>
relevant to your Shibboleth IDP federating with those publishers.<br>
<br>
> The attributes released from the IdP are: eduPersonEntitlement, eduPersonScopedAffiliation, and eduPersonTargetedID.<br>
<br>
Note that many publishers require some sort of set-up process to be<br>
completed. Sometimes that includes configuring exactly what attribute<br>
(and value/s) should be used by the platform for access control, in a<br>
self-service interface accessible only to selected representatives<br>
from the institution.<br>
<br>
This will differ for each publisher (which doesn't scale, of course).<br>
E.g. here are some resources for Springer:<br>
<br>
<a href="https://support.springer.com/en/support/solutions/articles/6000079288-shibboleth-access-for-institutions">https://support.springer.com/en/support/solutions/articles/6000079288-shibboleth-access-for-institutions</a><br>
and<br>
<a href="https://idp.springer.com/help/sso">https://idp.springer.com/help/sso</a><br>
<br>
> The Springer site, link.springer.com throws up an Application error with Issue reference number:<br>
> 1a4582-SAMLmessagevalidationfailedduringSingleSign-On<br>
<br>
You'd have to ask Springer Nature what their own error messages mean<br>
in detail. I have not encountered this myself with them so I couldn't say.<br>
<br>
If you don't have any contact details for the SP the SAML entity<br>
serving link.springer.com is "<a href="https://fsso.springer.com">https://fsso.springer.com</a>" and REFEDS<br>
MET has dozens of entries for that entity, most of which providing<br>
contact details:<br>
<a href="https://met.refeds.org/met/search_service/?entityid=https://fsso.springer.com">https://met.refeds.org/met/search_service/?entityid=https://fsso.springer.com</a><br>
E.g. my own registration lists "onlineservice@springernature.com" both<br>
for technical and support requests.<br>
<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>