<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Rhys Goodwin&#039;s Weblog</title>
	<atom:link href="http://blog.rhysgoodwin.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rhysgoodwin.com</link>
	<description>I AM the system administrator. Who do I call?</description>
	<lastBuildDate>Mon, 20 Feb 2012 14:07:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>Comment on SAML WebSSO &amp; Federation Made Easy by Oliver Wulff</title>
		<link>http://blog.rhysgoodwin.com/security/saml-websso-federation-made-easy/#comment-3077</link>
		<dc:creator>Oliver Wulff</dc:creator>
		<pubDate>Mon, 20 Feb 2012 14:07:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1126#comment-3077</guid>
		<description>Hi there
I&#039;m wondering what you think about the WS-Federation passive requestor profile (browser). The benefit I see is the re-use of the WS-Trust semantic and the decoupling to a specific SAML protocol version.
Instead of a samlp:response you get the RSTR of the WS-Trust STS. An additional benefit is the re-use of the STS for Web Services communication. Attribute based access control can be achieved by the Claims dialect standardized by WS-Trust and WS-Federation.
What do you think?</description>
		<content:encoded><![CDATA[<p>Hi there<br />
I&#8217;m wondering what you think about the WS-Federation passive requestor profile (browser). The benefit I see is the re-use of the WS-Trust semantic and the decoupling to a specific SAML protocol version.<br />
Instead of a samlp:response you get the RSTR of the WS-Trust STS. An additional benefit is the re-use of the STS for Web Services communication. Attribute based access control can be achieved by the Claims dialect standardized by WS-Trust and WS-Federation.<br />
What do you think?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ADFS 2.0 in Forest Trust Environment by RhysGoodwin</title>
		<link>http://blog.rhysgoodwin.com/windows-admin/adfs-2-0-in-a-forest-trust-environment/#comment-3073</link>
		<dc:creator>RhysGoodwin</dc:creator>
		<pubDate>Fri, 03 Feb 2012 10:23:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1236#comment-3073</guid>
		<description>Hi Kjell, When you say &quot;use an incorrect username/password&quot; - are you using forms based authentication or is the browser prompting for a username/password? Have you done  the Kerberos config and are there any firewalls between the adfs server and the domain controllers in in the worker domain?

Cheers,
Rhys</description>
		<content:encoded><![CDATA[<p>Hi Kjell, When you say &#8220;use an incorrect username/password&#8221; &#8211; are you using forms based authentication or is the browser prompting for a username/password? Have you done  the Kerberos config and are there any firewalls between the adfs server and the domain controllers in in the worker domain?</p>
<p>Cheers,<br />
Rhys</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ADFS 2.0 in Forest Trust Environment by Kjell</title>
		<link>http://blog.rhysgoodwin.com/windows-admin/adfs-2-0-in-a-forest-trust-environment/#comment-3070</link>
		<dc:creator>Kjell</dc:creator>
		<pubDate>Tue, 31 Jan 2012 09:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1236#comment-3070</guid>
		<description>Nice blog! I have encountered a problem in an scenario not much different from this one. 

AD1.worker.local
One way trust
AD1.student.local

I have an ADFS installed on the student side, and user.student.local can log in to the services without any problems. But user.worker.local can not logon. The fun part is that some traffic is going trough, If I use an incorrect password for user.worker.local it notices that the password is incorrect. But if I use an correct password I get an error.

&quot;The FA encountered an error during an attempt to  connect to a LDAP server at worker.local.&quot;

&quot;Event 111, AD FS 2.0
The FA Service encountered an error while processing the WS-Trust request&quot;




Keep up the good work.</description>
		<content:encoded><![CDATA[<p>Nice blog! I have encountered a problem in an scenario not much different from this one. </p>
<p>AD1.worker.local<br />
One way trust<br />
AD1.student.local</p>
<p>I have an ADFS installed on the student side, and user.student.local can log in to the services without any problems. But user.worker.local can not logon. The fun part is that some traffic is going trough, If I use an incorrect password for user.worker.local it notices that the password is incorrect. But if I use an correct password I get an error.</p>
<p>&#8220;The FA encountered an error during an attempt to  connect to a LDAP server at worker.local.&#8221;</p>
<p>&#8220;Event 111, AD FS 2.0<br />
The FA Service encountered an error while processing the WS-Trust request&#8221;</p>
<p>Keep up the good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Print Server Power Control Hack by Milan</title>
		<link>http://blog.rhysgoodwin.com/hardware/print-server-power-control-hack/#comment-2726</link>
		<dc:creator>Milan</dc:creator>
		<pubDate>Mon, 26 Dec 2011 00:02:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=94#comment-2726</guid>
		<description>hi,
i&#039;ve been cracking my brain about the setting the &quot;1.3.6.1.4.1.11.2.4.3.13.4.0&quot;  value to 2 with an SMTP tool and I just can&#039;t figure it out :( Could someone help me with this part, step by step. (from a Windows machine). Thanks in advance.

By the way: great job on the application.

cheers,
milan</description>
		<content:encoded><![CDATA[<p>hi,<br />
i&#8217;ve been cracking my brain about the setting the &#8220;1.3.6.1.4.1.11.2.4.3.13.4.0&#8243;  value to 2 with an SMTP tool and I just can&#8217;t figure it out <img src='http://blog.rhysgoodwin.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  Could someone help me with this part, step by step. (from a Windows machine). Thanks in advance.</p>
<p>By the way: great job on the application.</p>
<p>cheers,<br />
milan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindPrivateKey.exe (Pre-Compiled) by ConfigMgr Mixed Mode &#8211; Certificate Store, Export-Import Certificates, Private Key Files and Folder Details &#171; Anoop&#039;s</title>
		<link>http://blog.rhysgoodwin.com/windows-admin/findprivatekey-exe-pre-compiled/#comment-2661</link>
		<dc:creator>ConfigMgr Mixed Mode &#8211; Certificate Store, Export-Import Certificates, Private Key Files and Folder Details &#171; Anoop&#039;s</dc:creator>
		<pubDate>Wed, 21 Dec 2011 18:20:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1237#comment-2661</guid>
		<description>[...] Download FindPrivateKey.exe HERE [...]</description>
		<content:encoded><![CDATA[<p>[...] Download FindPrivateKey.exe HERE [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindPrivateKey.exe (Pre-Compiled) by ConfigMgr Mixed Mode &#8211; Certificate Store, Export-Import Certificates, Private Key Files and Folder Details</title>
		<link>http://blog.rhysgoodwin.com/windows-admin/findprivatekey-exe-pre-compiled/#comment-2660</link>
		<dc:creator>ConfigMgr Mixed Mode &#8211; Certificate Store, Export-Import Certificates, Private Key Files and Folder Details</dc:creator>
		<pubDate>Wed, 21 Dec 2011 18:16:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1237#comment-2660</guid>
		<description>[...] Download FindPrivateKey.exe HERE [...]</description>
		<content:encoded><![CDATA[<p>[...] Download FindPrivateKey.exe HERE [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SalesForce SSO with ADFS 2.0 &#8211; Everything you need to Know by RhysGoodwin</title>
		<link>http://blog.rhysgoodwin.com/cloud/salesforce-sso-with-adfs-2-0-everything-you-need-to-know/#comment-2373</link>
		<dc:creator>RhysGoodwin</dc:creator>
		<pubDate>Tue, 13 Dec 2011 22:32:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1135#comment-2373</guid>
		<description>Hi Pradeep, 
Having the same username and password between orgs won&#039;t help. 

You have ADFS 2.0 / SSO working for org1 and now you want it to work for org2 as well. Correct?

You&#039;ve got several different issues here and some more which you&#039;ll discover once you solve these ones I&#039;m sorry to say. 

One major problem is that ADFS 2.0 won&#039;t let you have more than one relying party with the same signing certificate which means you won&#039;t be able to have org1 and org2 set up separately with 2 separate idpinitiated urls.  Only way around this that I know of is to have a separate ADFS 2.0 servers.

You need to understand then and configure the kerberos SPNs. Have a look at this post for starters:
http://blog.rhysgoodwin.com/windows-admin/active-directory-and-kerberos-spns-made-easy/


You need to understand IE zones and configure them via GPO if you want IE to play nicely. 
Have a look at this post:
http://blog.rhysgoodwin.com/windows-admin/ie-gpo-zone-templates-and-the-open-file-security-warning/

Know that integrated login between IE and the ADFS server won&#039;t happen seamlessly if the ADFS server isn&#039;t part of the local intranet zone.

I still don&#039;t know much about your environment. 

After all this I suspect that what you really need is not ADFS 2.0 but to use org1 as an Idp for org2. I don&#039;t have any experience with this but I know it&#039;s possible.

Cheers,
Rhys</description>
		<content:encoded><![CDATA[<p>Hi Pradeep,<br />
Having the same username and password between orgs won&#8217;t help. </p>
<p>You have ADFS 2.0 / SSO working for org1 and now you want it to work for org2 as well. Correct?</p>
<p>You&#8217;ve got several different issues here and some more which you&#8217;ll discover once you solve these ones I&#8217;m sorry to say. </p>
<p>One major problem is that ADFS 2.0 won&#8217;t let you have more than one relying party with the same signing certificate which means you won&#8217;t be able to have org1 and org2 set up separately with 2 separate idpinitiated urls.  Only way around this that I know of is to have a separate ADFS 2.0 servers.</p>
<p>You need to understand then and configure the kerberos SPNs. Have a look at this post for starters:<br />
<a href="http://blog.rhysgoodwin.com/windows-admin/active-directory-and-kerberos-spns-made-easy/" rel="nofollow">http://blog.rhysgoodwin.com/windows-admin/active-directory-and-kerberos-spns-made-easy/</a></p>
<p>You need to understand IE zones and configure them via GPO if you want IE to play nicely.<br />
Have a look at this post:<br />
<a href="http://blog.rhysgoodwin.com/windows-admin/ie-gpo-zone-templates-and-the-open-file-security-warning/" rel="nofollow">http://blog.rhysgoodwin.com/windows-admin/ie-gpo-zone-templates-and-the-open-file-security-warning/</a></p>
<p>Know that integrated login between IE and the ADFS server won&#8217;t happen seamlessly if the ADFS server isn&#8217;t part of the local intranet zone.</p>
<p>I still don&#8217;t know much about your environment. </p>
<p>After all this I suspect that what you really need is not ADFS 2.0 but to use org1 as an Idp for org2. I don&#8217;t have any experience with this but I know it&#8217;s possible.</p>
<p>Cheers,<br />
Rhys</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SalesForce SSO with ADFS 2.0 &#8211; Everything you need to Know by RhysGoodwin</title>
		<link>http://blog.rhysgoodwin.com/cloud/salesforce-sso-with-adfs-2-0-everything-you-need-to-know/#comment-2368</link>
		<dc:creator>RhysGoodwin</dc:creator>
		<pubDate>Tue, 13 Dec 2011 20:55:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1135#comment-2368</guid>
		<description>Hi Tim, from memory I tested this and had it confirmed by SalesForce at the time. so I think this must be a new development. Thanks for pointing it out. I&#039;ve updated the post.

We actually ended up implementing our own JIT provisioning solution. Users first hit an in-house app that checks if they already have an account and if they don&#039;t it will create one for them using the SFDC API. The reason we did this is because we needed to take the user through a few steps to make sure that the details we had for them were correct before we created an account for them. Also email is an mandatory field for creating accounts but we don&#039;t have email addresses for all our users in AD so this method allows us to gather that information from the user.

Cheers,
Rhys</description>
		<content:encoded><![CDATA[<p>Hi Tim, from memory I tested this and had it confirmed by SalesForce at the time. so I think this must be a new development. Thanks for pointing it out. I&#8217;ve updated the post.</p>
<p>We actually ended up implementing our own JIT provisioning solution. Users first hit an in-house app that checks if they already have an account and if they don&#8217;t it will create one for them using the SFDC API. The reason we did this is because we needed to take the user through a few steps to make sure that the details we had for them were correct before we created an account for them. Also email is an mandatory field for creating accounts but we don&#8217;t have email addresses for all our users in AD so this method allows us to gather that information from the user.</p>
<p>Cheers,<br />
Rhys</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SalesForce SSO with ADFS 2.0 &#8211; Everything you need to Know by Pradeep Kumar</title>
		<link>http://blog.rhysgoodwin.com/cloud/salesforce-sso-with-adfs-2-0-everything-you-need-to-know/#comment-2355</link>
		<dc:creator>Pradeep Kumar</dc:creator>
		<pubDate>Tue, 13 Dec 2011 13:58:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1135#comment-2355</guid>
		<description>Hi Rhys,
Thanks for the reply.
My actual requirement Org1 should have a link .By click on that link Org2&#039;s sites should open a new window and the Org1&#039;s standard user should logged in on org2&#039;s sites.Because Org1&#039;s user have the same username as it in Org2&#039;s user object field like identifier.
I have used your blog to do ADFS server to Org2&#039;s Sites.
But ADFS Server and Org2&#039;s sites takes authentication when we click on link in Org1. I used domain name of Org2 as a link in Org1. ADFS server ask for the Username and password first time only.
I want ADFS server and Sites should not ask for the Login as Org1&#039;s Username same with Org2&#039;s User Identifier Field.
Can I use ADFS Server proxy for Forms Authentication on ADFS Server ?
I used Org2 is metadata File in Relying party trust.
What types of settings i should done?
I did not do anything kerberos configuration.
Please suggest me the best way to do this.
Thanks in advance 
Pradeep kumar</description>
		<content:encoded><![CDATA[<p>Hi Rhys,<br />
Thanks for the reply.<br />
My actual requirement Org1 should have a link .By click on that link Org2&#8242;s sites should open a new window and the Org1&#8242;s standard user should logged in on org2&#8242;s sites.Because Org1&#8242;s user have the same username as it in Org2&#8242;s user object field like identifier.<br />
I have used your blog to do ADFS server to Org2&#8242;s Sites.<br />
But ADFS Server and Org2&#8242;s sites takes authentication when we click on link in Org1. I used domain name of Org2 as a link in Org1. ADFS server ask for the Username and password first time only.<br />
I want ADFS server and Sites should not ask for the Login as Org1&#8242;s Username same with Org2&#8242;s User Identifier Field.<br />
Can I use ADFS Server proxy for Forms Authentication on ADFS Server ?<br />
I used Org2 is metadata File in Relying party trust.<br />
What types of settings i should done?<br />
I did not do anything kerberos configuration.<br />
Please suggest me the best way to do this.<br />
Thanks in advance<br />
Pradeep kumar</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SalesForce SSO with ADFS 2.0 &#8211; Everything you need to Know by RhysGoodwin</title>
		<link>http://blog.rhysgoodwin.com/cloud/salesforce-sso-with-adfs-2-0-everything-you-need-to-know/#comment-2332</link>
		<dc:creator>RhysGoodwin</dc:creator>
		<pubDate>Mon, 12 Dec 2011 23:50:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rhysgoodwin.com/?p=1135#comment-2332</guid>
		<description>Hi Pradeep, are you using ADFS 2.0 for the SSO on to org1? I have a feeling that you&#039;re not going to be able to do what you need using ADFS 2.0. 

If you are using internet explorer you shouldn&#039;t be prompted ADFS for a username/password. There are a number of things that could cause this. Have you done kerberos configuration?

Also the ADFS server needs to be classified in the local intranet zone to send your credentials. All of this about sending your domain credentials using Kerberos NOT send a username and password which was entered at a salesforce login page. I might be able to give you more advice but you&#039;d need to give me more of an overview of your environment. 

Cheers,
Rhys</description>
		<content:encoded><![CDATA[<p>Hi Pradeep, are you using ADFS 2.0 for the SSO on to org1? I have a feeling that you&#8217;re not going to be able to do what you need using ADFS 2.0. </p>
<p>If you are using internet explorer you shouldn&#8217;t be prompted ADFS for a username/password. There are a number of things that could cause this. Have you done kerberos configuration?</p>
<p>Also the ADFS server needs to be classified in the local intranet zone to send your credentials. All of this about sending your domain credentials using Kerberos NOT send a username and password which was entered at a salesforce login page. I might be able to give you more advice but you&#8217;d need to give me more of an overview of your environment. </p>
<p>Cheers,<br />
Rhys</p>
]]></content:encoded>
	</item>
</channel>
</rss>

