<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="#0563C1" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Thanks for your informative and quick reply Nate. It’s reassuring and helpful to have a short summary of steps.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">In the meantime, I’ve learned that our security team would prefer that I authenticate with our MSFT Azure IdP. However, based on your description of the steps and the metadata our security team sent me, I suspect that the process will be
the same.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Regards, Arthur<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><b>Nate Klingenstein</b> <a href="mailto:users%40shibboleth.net?Subject=Re:%20Re%3A%20Configure%20SP%20using%20Apache%20to%20access%20ADFS%20IdP&In-Reply-To=%3C0101017971ac1a18-7e347f76-25fc-4a36-856f-10f978423e89-000000%40us-west-2.amazonses.com%3E" title="Configure SP using Apache to access ADFS IdP">ndk
at signet.id</a><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Arthur,<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in">This should be relatively straightforward integration. You need to load the ADFS instance's metadata in the SP, ensure that ADFS trusts the SP, tell ADFS to release the proper attributes, ensure the proper attributes
are mapped to environment variables by the SP, and since this is a bilateral integration, add ADFS' entityID as the default in the SSO element in shibboleth2.xml. That last step or the enforcement of protection may be what you're missing in terms of how to
redirect the user directly to ADFS when authentication is required.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><a href="https://wiki.shibboleth.net/confluence/display/SP3/GettingStarted">https://wiki.shibboleth.net/confluence/display/SP3/GettingStarted</a><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><a href="https://wiki.shibboleth.net/confluence/display/SP3/ProtectContent">https://wiki.shibboleth.net/confluence/display/SP3/ProtectContent</a><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in">I'm not entirely sure what else to point you to. I hope this helps.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Best wishes,<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Nate.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in">--------<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Signet, Inc.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">The Art of Access ®<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><a href="https://www.signet.id/">https://www.signet.id</a><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">"Goldberg, Arthur P" <arthur.p.goldberg@mssm.edu><br>
<b>Date: </b>Saturday, May 15, 2021 at 2:26 PM<br>
<b>To: </b>"users@shibboleth.net" <users@shibboleth.net><br>
<b>Subject: </b>Configure SP using Apache to access ADFS IdP<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
</div>
<p class="MsoNormal" style="margin-left:.5in">Hello Shibboleth community<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">I’m a newcomer to Shibboleth, SAML2 and ADFS.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">I’m configuring a web app’s Service Provider. The web app runs on CentOS 7.9 and uses Apache 2.4 to handle authentication. Authentication will be provided by an ADFS service, which Mount Sinai operates as a cloud-based
Azure AD.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">I’ve read much of the great <a href="https://wiki.shibboleth.net/confluence/display/SP3/Home">
Shibboleth Service Provider documentation</a>, but remain confused about how to properly reference the ADFS service as a SAML 2 IdP.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">I’d greatly appreciate assistance if you have expertise in this combination of technologies.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Thanks<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Arthur<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in">-- <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:10.5pt;color:black">Arthur Goldberg, PhD<br>
Research Data Services<br>
Scientific Computing<br>
Associate Professor of Genetics and Genomic Sciences<br>
Institute for Data Science and Genomic Technology<br>
Mount Sinai School of Medicine</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:10.5pt;color:black"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:10.5pt;color:black"><a href="mailto:Arthur.Goldberg@mssm.edu">Arthur.Goldberg@mssm.edu</a></span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="color:black">646 526 5020<br>
Zoom: <a href="https://mssm.zoom.us/my/arthur.goldberg?pwd=LzByMGJOZC9wM3A2aHV6OU94eUtSQT09">https://mssm.zoom.us/my/arthur.goldberg?pwd=LzByMGJOZC9wM3A2aHV6OU94eUtSQT09</a></span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
</body>
</html>