<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;">Hi,</div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;"> </div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;">Thanks for your answer.</div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;"> </div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;">By "ShibSP" you mean a Shibboleth SP (shibd) and mod_shib enabled ? </div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;">If yes, how do you "play" with SAML ?The setup of these two components looks easy, but what to do next ?</div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;">I am looking for some app (not problem if it's CLI) I could download, as I don't really know where to start if I have to do it from scratch (Python guy here, deprecated Java memories and hello-world level minus in C).</div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;"> </div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;">I will have a look to <a href="https://samltest.id/" target="_blank" rel="noreferrer noopener">https://samltest.id/</a>  but I prefer some internal stuff first. A "download" link on their homepage would be nice, or something on Docke Hub :-)</div>
<div style="font-family: arial, helvetica,sans-serif; font-size: 10pt; color: #000000;"> </div>
<div>Regards<br /><br />Le 09-Nov-2022 14:25:33 +0100, users@shibboleth.net a écrit:</div>
<blockquote style="margin-left: 0; padding-left: 5px; border-left: 2px solid navy;">> Is there some tool a bit like "aacli" but able to mimic some kind of "dummy SP" ? Only sending forged SAML requests and getting the responses, just for debug and learning purpose.<br /><br />My team uses a small VM with a basic RHEL + apache + TLS + ShibSP installed that we use for testing SP things. I think there's also <a href="https://samltest.id/" target="_blank" rel="noreferrer noopener">https://samltest.id/</a> that some have used, but I haven't. I've used my small VM to build small SAML proof of concepts for golang, node, and whatever things our customers are trying to integrate with SSO.<br /><br />ShibSP is a very versatile SAML implementation. I recommend it over other implementations. But there are certainly others, like python, perl, and even bash.<br /><br />- Steve<br /><br />On 11/9/22, 8:19 AM, "users on behalf of Cantor, Scott via users" <<a href="mailto:users-bounces@shibboleth.net" target="_blank" rel="noreferrer noopener">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:users@shibboleth.net" target="_blank" rel="noreferrer noopener">users@shibboleth.net</a>> wrote:<br /><br />> We don't have any SP as far as I know. So I am trying to be ready for<br />> anything and learing with trial/errors. <br /><br />If you didn't have any SPs to worry about, you wouldn't need an IdP. And if you're really starting from scratch, this is not how to do it. Do NOT support things just because. That goes triple for pairwise ID constructs. Stop, undo, get rid of all of it, until you know what you're doing and why.<br /><br />Deploy what you require, when you're ready to support it.<br /><br />> Is there some tool a bit like "aacli" but able to mimic some kind of "dummy SP" ? Only sending forged SAML requests and getting the<br />> responses, just for debug and learning purpose.<br /><br />There's testshib.<br /><br />-- Scott<br /><br /><br />-- <br />For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;" target="_blank" rel="noreferrer noopener">https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;</a>!!IBzWLUs!SzyQyvR4f8VotPhHBk5bh_WRkWyQ-0fXVGw-fKP6ZJgB3FVWHTZ9mGSQ7lHfNi8a-wLyHiuaYDJnL_Sg$ <br />To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer noopener">users-unsubscribe@shibboleth.net</a><br /><br />-- <br />For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" target="_blank" rel="noreferrer noopener">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br />To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer noopener">users-unsubscribe@shibboleth.net</a></blockquote>
                    <br/><hr>FreeMail powered by <a href="https://mail.fr" target="_blank">mail.fr</a>