<html dir="ltr"><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="text-align:left; direction:ltr;"><div>Hi Nick,</div><div><br></div><div>It might be a little off topic, but hoping I can steer you in the direction of getting some help...</div><div><br></div><div>Assuming shib.name-of-college.ac.uk, is a UK federation member, but even if it's not, then you are and your SAML SP / entity is registered with us.... Can you raise a call with the our team at Jisc supporting the UK federation via <a href="mailto:service@ukfederation.org.uk">service@ukfederation.org.uk</a> please <br>(<a href="https://www.ukfederation.org.uk/content/Documents/FedSupport#helpdesk">https://www.ukfederation.org.uk/content/Documents/FedSupport#helpdesk</a>)?</div><div><br></div><div>If you are able to ask the customer to test with a test service e.g. <a href="https://test.ukfederation.org.uk">https://test.ukfederation.org.uk</a> (I'm thinking they'll have the same problem!), and also tell us on that message (off list) who name-of-college.ac.uk are please (and if it's not a UK federation member, we can steer you to the other eduGAIN federation involved for support)</div><div><br></div><div>Other thoughts..</div><div><br></div><div>- Other SAML is probably via Azure/Entra ID direct, rather than via their Shibboleth Identity provider.</div><div>- 403 forbidden is not a shock , the IdP is for most deployments hosted at /idp</div><div>- I'd suspect it's the issue of the IdP being hosted internally or "in a DMZ" combined with DNS, maybe DNS over https getting in the way, firewalls not translating traffic which arrives from not the internet etc..</div><div><br></div><div>Kind regards,</div><div><br></div><div>Jon</div><div><span><div style="width: 71ch;"><br></div><div style="width: 71ch;">Jon Agland</div><div style="width: 71ch;">Technical Services Manager - Trust and Identity</div><div style="width: 71ch;">T 02038198207</div><div style="width: 71ch;">M 07443984222</div><div style="width: 71ch;">Lumen House, Library Avenue, Harwell Oxford, Didcot, OX11 0SG</div><div style="width: 71ch;"><br></div><div style="width: 71ch;"><a href="https://www.jisc.ac.uk/trust-and-identity">https://www.jisc.ac.uk/trust-and-identity</a></div><div style="width: 71ch;"><a href="https://www.ukfederation.org.uk">https://www.ukfederation.org.uk</a></div><div style="width: 71ch;"> </div><div style="width: 71ch;">Jisc is a registered charity (number 1149740) and a company limited by</div><div style="width: 71ch;">guarantee which is registered in England under company number.</div><div style="width: 71ch;">05747339, VAT number GB 197 0632 86. Jisc’s registered office is: 4</div><div style="width: 71ch;">Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.</div><div style="width: 71ch;"><br></div><div style="width: 71ch;">Jisc Services Limited is a wholly owned Jisc subsidiary and a company</div><div style="width: 71ch;">limited by guarantee which is registered in England under company</div><div style="width: 71ch;">number 02881024, VAT number GB 197 0632 86. The registered office is: 4</div><div style="width: 71ch;">Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.</div><div style="width: 71ch;"> </div></span></div><div><br></div><div>On Thu, 2023-10-12 at 12:42 +0100, Nick Myers via users wrote:</div><blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex"><div dir="ltr"><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">Hello,</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">Please reject this message or don't reply if this is not an appropriate question to ask here. I'm trying to help someone that is using Shibboleth in front of on Azure AD Enterprise App, and when using IOS devices on one Wifi network, Redirect requests the browser makes to their Shibboleth host time out.</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">I use Okta to provide our SAML Service Provider capabilities, with a Cirrus Proxy to provide Federated SAML via the likes of Edugain, InCommon, etc. This is working well for 1500+ customers.<br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">We have a customer who explains that:</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><ul><li>On iPad and iOS devices,</li><li>When connected to a specific Wifi network (doesn't happen on mobile network, or other Wifi networks)</li><li>When the Redirect request occurs from to their host (<span style="font-family:Arial,Helvetica,sans-serif"><a href="https://shib.name-of-college.ac.uk">https://shib.name-of-college.ac.uk</a>)</span></li><li><span style="font-family:Arial,Helvetica,sans-serif">The request always times out (Safari and Chrome)</span></li></ul></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><span style="font-family:Arial,Helvetica,sans-serif">This does not happen on other networks, or on non-iOS devices on the specific Wifi network experiencing the issue.</span><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">The customer's own IT folk are not accepting my conclusion that there must be something about the connectivity to the Shib host, network, or DNS resolution, affecting those devices, and are telling me that "all of our other SAML SSO logins with other vendors work fine, it's just your service".</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">I wondered whether anyone had experienced this particular issue, perhaps this is not an uncommon issue for iOS devices.</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">I have asked them to use their iOS devices, and go to <a href="https://shib.name-of-college.ac.uk">https://shib.name-of-college.ac.uk</a> directly, which also times out (it should display a 403 Forbidden). I think this proves that these devices are being prevented from connecting, but the customer IT folk are insistent this is not the case and assigning responsibility to our service.</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">Thank you for taking the time to read, and again, my apologies if this is off-topic for the group.</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small">Best<br>Nick</div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;font-size:small"><br></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="line-height:18px;color:rgb(0,0,0)"><p style="font-family:"Myriad Pro",Arial,sans-serif"></p></div></div></div></div></div></div></div></div></div></div>
</blockquote></body></html>