Re: [SOGo] Re: SAML2 authentication requirements

2013-07-01 Thread Stephen Ingram
On Sat, Jun 29, 2013 at 6:13 AM, Ludovic Marcotte lmarco...@inverse.cawrote: On 2013-06-29 1:57 AM, Stephen Ingram wrote: The makefile in SoObjects/SOGo (line 149) indicates the presence of this metadata file, but there is none. The code in SOGoSAML2Session also appears to look for this

Re: [SOGo] Re: SAML2 authentication requirements

2013-06-29 Thread Ludovic Marcotte
On 2013-06-29 1:57 AM, Stephen Ingram wrote: The makefile in SoObjects/SOGo (line 149) indicates the presence of this metadata file, but there is none. The code in SOGoSAML2Session also appears to look for this file (SOGoSAML2Metadata.xml). Does this need to be added before compiling? I've

Re: [SOGo] Re: SAML2 authentication requirements

2013-06-18 Thread Ludovic Marcotte
On 2013-06-17 4:53 PM, Stephen Ingram wrote: Maybe you've made some changes since in the nightlies, but even trying to retrieve the metadata didn't work for me with version 2.0.5a. Going to http://hostname/SOGo/saml2-metadata produces a blank page and the login page itself produces the

Re: [SOGo] Re: SAML2 authentication requirements

2013-06-17 Thread Stephen Ingram
On Thu, May 23, 2013 at 6:41 AM, Moussa NOMBRÉ moussa.nom...@auf.orgwrote: We worked on SOGo/SAML with Inverse. We've got something almost functional, but there still have some important bugs. Currently, the project is not completed. I'm guessing that Inverse is aware that SAML does not

Re: [SOGo] Re: SAML2 authentication requirements

2013-06-17 Thread Ludovic Marcotte
On 2013-06-17 3:55 PM, Stephen Ingram wrote: I'm guessing that Inverse is aware that SAML does not work with SOGo then? Are you working on a paid or sponsored project with them to add this feature? SAML2 *does work* with SOGo. It's just that some features aren't present, like the logout

Re: [SOGo] Re: SAML2 authentication requirements

2013-06-17 Thread Stephen Ingram
On Mon, Jun 17, 2013 at 12:58 PM, Ludovic Marcotte lmarco...@inverse.cawrote: On 2013-06-17 3:55 PM, Stephen Ingram wrote: I'm guessing that Inverse is aware that SAML does not work with SOGo then? Are you working on a paid or sponsored project with them to add this feature? SAML2 *does

Re: [SOGo] Re: SAML2 authentication requirements

2013-05-23 Thread Moussa NOMBRÉ
Hi, We worked on SOGo/SAML with Inverse. We've got something almost functional, but there still have some important bugs. Currently, the project is not completed. I think, that's why Inverse has disable SAML support in SOGo 2.0.5 : don't build SAML support on debian yet

Re: [SOGo] Re: SAML2 authentication requirements

2013-05-23 Thread Stephen Ingram
Moussa- Thank you. That is an excellent writeup. I had come to the same conclusion that SAML wasn't working in SOGo yet. I saw that SAML was disabled in Debian builds, but I'm using CentOS so I didn't think it applied to me. I was thinking there are packaging issues with CentOS as well, but,

[SOGo] Re: SAML2 authentication requirements

2013-05-22 Thread Stephen Ingram
After looking more closely at Lasso, it appears that Lasso itself it supposed to provide the functionality of a SP, it just doesn't work. First, the configuration information (from the SOGo manual) is incorrect. The SOGoSAML2IdpCertificateLocation is really the CA certificate of the IdP, not the