Jump to:
To configure your SAML V2 service provider(SP) to use the InCommon Federation Discovery Service, first make sure your SP software supports the SAML V2.0 Identity Provider Discovery Protocol, then:
One. | Configure your SP's metadata to include one or more |
---|---|
Two. | Make sure your SP's metadata has one or more SAML V2.0 <md:AsssertionConsumerService> endpoints in your metadata. This is also required to successfully integrate with the InCommon Discovery Service. |
Three. | Fill out the MDUI section of the metadata completely and with care. The Discovery Service will at least display the DisplayName in your SP metadata to the user. The name should be clear and distinct enough so that the user can intuitively understand which service they are signing into. Good example: University of America Zoom Video Conference Service Bad example: Zoom |
Four. | Configure your SP to point to the InCommon Federation Discovery Service. The InCommon Federation Discovery Service is located at: https://wayf.incommonfederation.org/DS/WAYF Related: 2024-04-05_19-15-42_Configuring Shibboleth SP for discovery |
If your SP is registered in InCommon, use Federation Manager to edit your metadata to include at least one Discovery Response Endpoint:
The Discovery Response Endpoint, or the "Location" attribute in the <idpdisc:DiscoveryResponse> metadata element, is a return address at the SP. Once a user has selected their preferred identity provider, the Discovery Service returns to the SP's Discovery Response Endpoint to convey the user's preferred IDP.
To ensure the integrity of the sign-in interaction, the InCommon Federation Discovery Service will only redirect the user's browser agent to a SP's trusted Discovery Response endpoint published in the SP's InCommon metadata entry.
The InCommon Federation no longer recommends using SAML v1.1. Please update your service provider to Use SAML v2.0.
The namespace and binding attributes attached to the <idpdisc:DiscoveryResponse>
element are defined in the SAML V2.0 Identity Provider Discovery Protocol and Profile specification.
The InCommon Discovery Service is a deployment of the SWITCHwayf software implementation, a software project of the SWITCH federation.
Visit the 2024-04-05_19-15-41_Discovery Service FAQ for more information about the InCommon Federation Discovery Service.
Can't find what you are looking for?