[Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Bernard Paris
Hi devs, We want to use Shibboleth as an identity provider for API manager V.3. In the carbon console, via the IdP list, we have added an IdP entry then under "Federated Authenticators section and the SAML2 Web SSO Configuration section" we have configured our Shibboleth as identity provider.

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Sathya Bandara
Hi Bernard, You can upload the certificate into the 'Identity Provider Public Certificate' which is available under the 'Basic Information' section of Identity Provider configuration. Thanks, On Wed, Jan 15, 2020 at 8:19 PM Bernard Paris wrote: > Hi devs, > > We want to use Shibboleth as an id

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Bernard Paris
Hello, I understood that the certificate defined into the 'Identity Provider Public Certificate' is the public shibboleth certificate needed to decrypt the incoming SAML responses. It was automatically set when I loaded the shibboleth metadata.xml file under " SAML2 Web SSO Configuration" >

Re: [Dev] Shibboleth as an identity provider for APIM-3

2020-01-15 Thread Sathya Bandara
Hi Bernard, Shibboleth server public certificate configured in IDP config is used to verify the signature of SAML responses coming from Shibboleth. When configuring WSO2 as a SP in shibboleth, you need to give WSO2 server’s public certificate (in wso2carbon.jks). If you have enabled assertion enc