SimonInOz Posted March 6, 2020 Posted March 6, 2020 (edited) I have solved this myself, the 'redirect' URL did not match the text of the one in the relying party trusts list.... simple fix. Hi, We have setup SSO with an organisation called Jacplus. The sign on works, sort of, by passing through to our ADFS server and then displaying all of the Relying Party Trusts that we have in a dropdown box to select it from. Is there a way to pass this through without displaying a list? This is the URL we use: https://server.domain.edu/adfs/ls/IdpInitiatedSignOn.aspx?loginToRp=https://jacplus.com.au (domain changed) Here is what the end result is. Not an expert at this, so if you could explain what might need to happen it would be appreciated. Sorry image looks a bit small, no idea how to make it bigger. Can anyone assist? Edited March 6, 2020 by SimonInOz
HPlum78 Posted March 6, 2020 Posted March 6, 2020 You need to get a WAYF (less) url by the looks of things. That page that you are hitting, is in that selection box is that the org name or is that from you ADFS box using idp imitated sign on? (i cannot tell from the image). I guess my other question is do you use Azure? and if so could you not use that I would now advocate moving away from using ADFS for a lot of reasons. If its an on prem app that you want to support via Azure app proxy is the way to go now (you only need one app proxy box, this can support multiple apps)
SimonInOz Posted March 27, 2020 Author Posted March 27, 2020 I actually solved this one. Turns out the logintoRP parameter has to match the name of the relying party trust name in the ADFS console.. in my case, it was named "www.jacplus.com.au" Just in case anyone else has an issue of this type..
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now