<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body>
<div>
<div>
<div dir="ltr" data-ogsc="" style="">
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
Thanks for the feedback Peter and Mark</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
I should note this is my first Shibboleth SP for me. I usually just do IDP setup. </div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
So Without touching the handlerURL in the SP I am seeing successful authentication request from between the Shib SP and Shib IdP. In the IdP logs I can see the correct attributes passed to the SP.</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
But then in the website experience I get the IDP error page “web login service - unable to respond”.</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
So at this point the vendor of the application said the consumer URL from the SP had to be that specific URL I shared. This doesn’t seem to be the case. It seems to be an issue between the SP not knowing where to redirect after authentication. If the SP and
IdP are communicating correctly it is something between the app and SP right? </div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
Thanks,</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div dir="ltr" style="color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
Brent</div>
</div>
</div>
<div><br>
</div>
<div class="ms-outlook-ios-signature">Get <a href="https://aka.ms/o0ukef">Outlook for iOS</a></div>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Saturday, April 3, 2021 5:40:16 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> [EXTERNAL] Re: SP handlerURL modification not working</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">[External Email From]: users-bounces@shibboleth.net<br>
<br>
* Brent Goebel <Brent.Goebel@du.edu> [2021-04-03 00:07]:<br>
> Ellucian is saying that the Consumer Assertion URL needs to be<br>
> https://<hostname>/AppXtender/BdmSamlSso. So on their application<br>
> they are looking for this URL format.<br>
<br>
The only way this makes any sense is if they are acting as SAML SP and<br>
will be decoding (and possibly decrypting) and processing the SAML<br>
themselfs. Which is fine, it just doesn't have anything to do with<br>
(and there'd be no need for) the Shibboleth SP software.<br>
<br>
You can probably use their application (and whatever SAML 2.0 WebSSO<br>
support that comes with it) with the Shibboleth IDP ("Identity<br>
Provider") software, if you're running that. Maybe someone is<br>
confusing those two.<br>
<br>
> I already asked if they could modify their application code to take<br>
> https://<hostname>/Shibboleth.sso/SAML2/POST and they there is no<br>
> way to edit the expected Assertion URL on the application side. It<br>
> has to match this AppXtender/BdmSamlSso.<br>
<br>
Then I guess that's simply their SAML endpoint. Feed that to your SAML<br>
IDP and forget about the Shibboleth SP.<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!NCZxaNi9jForCP_SxBKJCA!GRw7uwXqSsaFhxQk27NGphqanaNhVYYz2W3JznuhMtWF3uCSQY5c-O7tNNXjQQeW1A$">
https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!NCZxaNi9jForCP_SxBKJCA!GRw7uwXqSsaFhxQk27NGphqanaNhVYYz2W3JznuhMtWF3uCSQY5c-O7tNNXjQQeW1A$</a>
<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>