<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Dr Robert, thanks a ton, your suggestion has resolved our long-pending issue. We are now able to access all the platforms without an issue.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Yes, we had upgraded to IdP v4 and switched to Azure AD at the same time.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks once again, and sorry about the delay in my reply. Unfortunately, the list email had landed in my junk folder!</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Cheers, Francis</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Robert Bradley <robert.bradley@it.ox.ac.uk><br>
<b>Sent:</b> 23 February 2021 20:49<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Access issue with some publisher platforms</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">External Email<br>
<br>
<br>
On 20/02/2021 13:38, Francis Jayakanth via users wrote:<br>
> HI, we are using Shibboleth IdP 4.0.1 along with Azure AD tenant to<br>
> facilitate federated access to subscribed online resources from the<br>
> various publishers like Elsevier, ACS, Wiley etc. While the access is<br>
> working fine on most of the publishers' platforms, we are having issues<br>
> with a few platforms that include Springer Link, Springer Nature (for<br>
> Nature branded journals), and Web of Science.<br>
><br>
> The attributes released from the IdP are: eduPersonEntitlement,<br>
> eduPersonScopedAffiliation, and eduPersonTargetedID.<br>
><br>
> The Springer site, link.springer.com throws up an Application error with<br>
> Issue reference number:<br>
> 1a4582-SAMLmessagevalidationfailedduringSingleSign-On<br>
><br>
> Can anyone help us to resolve the issue?<br>
><br>
<br>
I'm not sure if it helps, but if you did the upgrade to IdP v4 at the<br>
same time as the switch to using Azure AD and the IdP's SAML flow for<br>
authentication, it's possible that it's actually objecting to the IdP<br>
attempting to use GCM encryption. If that's the case, try setting:<br>
<br>
idp.encryption.config=shibboleth.EncryptionConfiguration.CBC<br>
<br>
in idp.properties and see if that helps.<br>
<br>
--<br>
Dr Robert Bradley<br>
Identity and Access Management Team, IT Services, University of Oxford<br>
<br>
</div>
</span></font></div>
</div>
</body>
</html>