<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">We are allowing their release of the persistent nameID which is just our standard persistent ID (a sha1 hash of a salted UUID). As well I’m releasing:<br>
uid, displayName, mail and groupMembership (for authorization in BT)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I’m doing nothing special in relying party or in their metadata, was a really easy setup from what I recall.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Hope that helps,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">--Joel<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">users <users-bounces@shibboleth.net> on behalf of IAM David Bantz via users <users@shibboleth.net><br>
<b>Date: </b>Thursday, October 13, 2022 at 2:40 PM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Cc: </b>IAM David Bantz <dabantz@alaska.edu><br>
<b>Subject: </b>Bomgar/BeyondTrust relying party?<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL EMAIL</span></strong><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Have you successfully configured Bomgar (BeyondTrust) for SSO via your Shibb IdP ?<o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Bomgar (BeyondTrust) has a GUI for SAML SSO integration that is mostly clear and straightforward,<o:p></o:p></p>
<div>
<p class="MsoNormal">but seemingly appropriate SAML assertions trigger “Authentication Failed” message at the service<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">(with no further details).<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Incoming SAML request specifies a nameid-format:persistent (not mentioned in the GUI) so<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">I configured release of nameID based on uid (unscoped username) and ePPN (same username, @<a href="http://alaska.edu">alaska.edu</a>)<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">with the requested format. Neither alternative produced anything further than “Authentication Failed” at the service.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Support has so far been less than useless. Perhaps you know an additional unmentioned requirement or trick?<o:p></o:p></p>
</div>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">David St Pierre Bantz<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">U Alaska IAM<o:p></o:p></p>
</div>
</div>
</div>
</body>
</html>