<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:"Segoe UI";
        panose-1:2 11 5 2 4 2 4 2 2 3;}
/* Style Definitions */
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:"Calibri",sans-serif;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:12.0pt;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoPlainText">Thanks again Nate.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">I found a helpful <span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#24292E">
article on <a href="https://rohanislam2.medium.com/azure-ad-saml-federation-using-shibboleth-sp-ad40f9c94eab">Azure AD SAML federation using Shibboleth SP</a>. Based on its recipe I had the Azure folks re-issue me a metadata file for the Azure identity provider.
 That resolved the problem below and got SSO working!<o:p></o:p></span></p>
<p class="MsoPlainText"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#24292E"><o:p> </o:p></span></p>
<p class="MsoPlainText"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#24292E">Regards<o:p></o:p></span></p>
<p class="MsoPlainText"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:#24292E">Arthur<o:p></o:p></span></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">On 5/24/21, 7:56 PM, "users on behalf of Nate Klingenstein" <users-bounces@shibboleth.net on behalf of ndk@signet.id> wrote:<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">    USE CAUTION: External Message.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">    Arthur,<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">    Shibboleth treats the certificate as a bag for a public key and little more.  Trust is based on metadata.  The private key that is being used to sign messages from the IdP doesn't match any valid public key in the IdP's metadata
 as loaded by the SP.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">   https://urldefense.proofpoint.com/v2/url?u=https-3A__samltest.id_faq_&d=DwICAg&c=shNJtf5dKgNcPZ6Yh64b-A&r=ZCkl1RSA6OLXGMeLhWIeG8wvWwYPCSABQEpGFXsWEJg&m=o-Njom8BS94HvUtNepTBW2KxAcTZVEk4DWdoQ67zHcM&s=v_X52L1sK94AzXzf-ih1UfYOUHHXvQh8o2a69UffwCw&e=<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">    Take care,<o:p></o:p></p>
<p class="MsoPlainText">    Nate.<o:p></o:p></p>
<p class="MsoPlainText">    --<o:p></o:p></p>
<p class="MsoPlainText">    For Consortium Member technical support, see https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=shNJtf5dKgNcPZ6Yh64b-A&r=ZCkl1RSA6OLXGMeLhWIeG8wvWwYPCSABQEpGFXsWEJg&m=o-Njom8BS94HvUtNepTBW2KxAcTZVEk4DWdoQ67zHcM&s=bVZ3f49z_ZpjTbAL7UWn9g5atVkM0YSFneQlffABa-Q&e=<o:p></o:p></p>
<p class="MsoPlainText">    To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<o:p></o:p></p>
</div>
</body>
</html>