<div dir="ltr"><div dir="ltr">Mohamed,</div><div dir="ltr"><br></div><div dir="ltr">Your guesses were right, but they're signing their authentication requests (above and beyond in all the wrong ways).  Your IdP will be unable to verify the signature -- or use the AuthnRequest -- unless you have the correct signing certificate included in the SP metadata that you wrote.</div><div dir="ltr"><br></div><div dir="ltr">It's almost always possible to configure your IdP to work with these SPs.  It's just... challenging.<br><div><br></div><div>Hope this helps,</div><div>Nate</div><div><br></div><div><br></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Mar 3, 2023 at 11:22 AM Mohamed Lrhazi via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Hello,<br><div><br></div><div>I am trying to add a new SP to our IdP... the SP is very uncooperative :(</div><div>they provide no metadata, no entityid... etc. Their UI just has to fields for me to fill:</div><div><br></div><div><font face="monospace">Entry point is the URL of your school's SAML server endpoint that will perform Single Sign On authentication. Acadeum will redirect your students to this URL when performing Single Sign On login. After your SAML server has authenticated the student, it will redirect back to Acadeum with the student's info such as their email address.</font><br></div><div><br></div><div><font face="monospace">Certificate *<br>The certificate of your school's SAML server that will be used to validate the authenticity and integrity of SAML messages received from your school's SAML server. The certificate is generated from your school's SAML server private key that is used to sign outgoing SAML messages<br></font></div><div><br></div><div><br></div><div>so I tried entering our IdP signing certificate and for entry point I tried :<br><br><a href="https://idp.cua.edu/idp/profile/SAML2/Redirect/SSO" target="_blank">https://idp.cua.edu/idp/profile/SAML2/Redirect/SSO</a><br><br>This causes their UI to redirect my browser to perform a SAML login... and our IdP errors out : A non-proceed event occurred while processing the request: MessageAuthenticationError</div><div><br></div><div>I created and added a metadata file for this SP, using the entity ID I see them using in their SAML request attempts.... <br><br>Their GET request contains some extra params, in addition to the SAMLRequest:</div><div><br></div><div><ol role="group" style="box-sizing:border-box;min-width:0px;min-height:0px;list-style-type:none;padding-left:10px;padding-bottom:5px;color:rgb(32,33,36);font-family:"Segoe UI",Tahoma,sans-serif;font-size:12px"><li title="" role="treeitem" style="box-sizing:border-box;min-width:0px;min-height:12px;text-overflow:ellipsis;white-space:nowrap;display:block;padding-left:5px;line-height:20px;margin-top:1px;margin-left:10px"><div style="box-sizing:border-box;min-width:0px;min-height:0px;display:inline-flex;margin-right:0.25em;font-weight:bold;vertical-align:top;white-space:pre-wrap">RelayState: </div><span style="box-sizing:border-box;min-width:0px;min-height:0px"></span><div style="box-sizing:border-box;min-width:0px;min-height:0px;white-space:pre-wrap;display:inline;margin-right:1em;word-break:break-all;margin-top:1px">{"institutionId":000,"redirectTo":"/settings/authentication","redirectToWebsite":"courseshare","singleSignOnSetupToken":"00965f0....d06af2"}</div></li><li title="" role="treeitem" style="box-sizing:border-box;min-width:0px;min-height:12px;text-overflow:ellipsis;white-space:nowrap;display:block;padding-left:5px;line-height:20px;margin-top:1px;margin-left:10px"><div style="box-sizing:border-box;min-width:0px;min-height:0px;display:inline-flex;margin-right:0.25em;font-weight:bold;vertical-align:top;white-space:pre-wrap">SigAlg: </div><span style="box-sizing:border-box;min-width:0px;min-height:0px"></span><div style="box-sizing:border-box;min-width:0px;min-height:0px;white-space:pre-wrap;display:inline;margin-right:1em;word-break:break-all;margin-top:1px"><a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1" target="_blank">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a></div></li><li title="" role="treeitem" style="box-sizing:border-box;min-width:0px;min-height:12px;text-overflow:ellipsis;white-space:nowrap;display:block;padding-left:5px;line-height:20px;margin-top:1px;margin-left:10px"><div style="box-sizing:border-box;min-width:0px;min-height:0px;display:inline-flex;margin-right:0.25em;font-weight:bold;vertical-align:top;white-space:pre-wrap">Signature: </div><span style="box-sizing:border-box;min-width:0px;min-height:0px"></span><div style="box-sizing:border-box;min-width:0px;min-height:0px;white-space:pre-wrap;display:inline;margin-right:1em;word-break:break-all;margin-top:1px">AYeGoLLzUEVyShLw....</div></li></ol><br>Is it possible to configure our IdP to work with such SP ?</div><div><br></div><div>Thanks,</div><div>Mohamed.</div><div><br><br></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>