﻿<?xml version="1.0" encoding="utf-8"?><rss xmlns:a10="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Microsoft Connect: Most Recent Feedback - Windows Identity Foundation Extensions</title><link>http://connect.microsoft.com/site1168/Feedback</link><description>Microsoft Connect: Most Recent Feedback - Windows Identity Foundation Extensions</description><language>en</language><copyright>&amp;#169; 2013 Microsoft Corporation. All rights reserved.</copyright><lastBuildDate>Sun, 19 May 2013 19:32:24 -0700</lastBuildDate><image><url>/Images/MSConnect_Logo.gif</url><title>Microsoft Connect: Most Recent Feedback - Windows Identity Foundation Extensions</title><link>http://connect.microsoft.com/site1168/Feedback</link></image><ttl>60</ttl><item><guid isPermaLink="false">763742</guid><link>http://connect.microsoft.com/site1168/feedback/details/763742/error-when-enumerating-through-claims-collection</link><author>MonkeyTennis</author><category>Bug</category><title>Error when enumerating through claims collection</title><description>Intermittently we see the following error when browsing a website:

Collection was modified; enumeration operation may not execute.
Exception type:
System.InvalidOperationException
StackTrace:
at System.Collections.Generic.List`1.Enumerator.MoveNextRare()
at Microsoft.IdentityModel.Claims.ClaimCollection.CopyWithSubject(IClaimsIdentity subject)
at Microsoft.IdentityModel.Claims.WindowsClaimsIdentity.Copy()
at Microsoft.IdentityModel.Claims.WindowsClaimsPrincipal..ctor(WindowsClaimsIdentity ident...&lt;BR&gt;&lt;BR&gt;Status: Active, 4 Up-Votes, 0 Down-Votes, 2 validations, 0 workarounds, 1 comment, feedback id: 763742</description><a10:updated>2012-09-20T05:27:36-07:00</a10:updated></item><item><guid isPermaLink="false">741335</guid><link>http://connect.microsoft.com/site1168/feedback/details/741335/integration-with-sharepoint-2010</link><author>Joseph Scarano</author><category>Bug</category><title>Integration with SharePoint 2010</title><description>Are these extensions compatible with SharePoint 2010? &lt;BR&gt;&lt;BR&gt;Status: Active, 2 Up-Votes, 0 Down-Votes, 0 validations, 0 workarounds, 1 comment, feedback id: 741335</description><a10:updated>2012-05-09T06:36:28-07:00</a10:updated></item><item><guid isPermaLink="false">733737</guid><link>http://connect.microsoft.com/site1168/feedback/details/733737/adfs-c2wts-identity-impersonation-failure-after-an-iis-reset</link><author>MonkeyTennis</author><category>Bug</category><title>ADFS/C2WTS identity impersonation failure after an IIS reset</title><description>The problem is easily reproduced using the following steps:
•Create an empty ASP.NET website and set up federation with ADFS
◦Ensure that a UPN claim is emitted by ADFS
•Modify C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe.config to allow access to authenticated users 
•Start the C2WTS service via start-run-services.msc
•Modify the ASP.NET web.config file to enable identity impersonation
•Log in via ADFS
•Perform an IIS reset
•Refresh the page
 
The following error will occur:
...&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 2 workarounds, 0 comments, feedback id: 733737</description><a10:updated>2012-03-27T15:17:24-07:00</a10:updated></item><item><guid isPermaLink="false">731837</guid><link>http://connect.microsoft.com/site1168/feedback/details/731837/need-for-extend-enum-values-of-microsoft-identitymodel-protocols-oauth-client-authorizationresponsetype</link><author>Naohiro Fujie</author><category>Bug</category><title>Need for extend enum values of Microsoft.IdentityModel.Protocols.OAuth.Client.AuthorizationResponseType</title><description>In the WIF extension for OAuth, the values of Microsoft.IdentityModel.Protocols.OAuth.Client.AuthorizationResponseType are fixed to 'code','token','code and token', but in the real world, some extensions for the specification of OAuth such as OpenID Connect are proceeding.
For example, I want to set 'id_token' as the response type parameter of  OAuthClient.RedirectToEndUserEndpoint() method to connect openid provider endpoint supporting openid connect, but now its parameter does not support cust...&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 731837</description><a10:updated>2012-03-18T08:52:26-07:00</a10:updated></item><item><guid isPermaLink="false">714031</guid><link>http://connect.microsoft.com/site1168/feedback/details/714031/will-these-extensions-ever-see-the-light-of-day</link><author>jgrenier</author><category>Bug</category><title>Will these extensions ever see the light of day?</title><description>It has been seven months since the SAML 2.0 extensions CTP was released, and not a word from the WIF team on whether or when they will be RTM (or if there will be another CTP). I have spent the last month working around the lack of SAML 2.0 protocol support in the current version of WIF. This after spending some time working with the extensions then realizing that I could not recommend their use when there is absolutely no communication from Microsoft to the developer community regarding their r...&lt;BR&gt;&lt;BR&gt;Status: Active, 6 Up-Votes, 0 Down-Votes, 0 validations, 0 workarounds, 1 comment, feedback id: 714031</description><a10:updated>2011-12-14T11:49:36-08:00</a10:updated></item><item><guid isPermaLink="false">703417</guid><link>http://connect.microsoft.com/site1168/feedback/details/703417/schedule-and-release</link><author>Bobby_D</author><category>Bug</category><title>Schedule and release</title><description>We really appreciate these extensions having been released.  I have some customers interested in using these libraries as soonas possible but I am hesitant to use them in a production environment because of the licensing restrictions.  I checked MSDN as well as the web in general and have not seen a release date for these extensions.  Is there any word yet on when/whether we can use these extensions in production?&lt;BR&gt;&lt;BR&gt;Status: Active, 5 Up-Votes, 0 Down-Votes, 0 validations, 0 workarounds, 2 comments, feedback id: 703417</description><a10:updated>2011-11-14T06:42:26-08:00</a10:updated></item><item><guid isPermaLink="false">700944</guid><link>http://connect.microsoft.com/site1168/feedback/details/700944/test</link><author>roiderevez</author><category>Bug</category><title>Test</title><description>Test&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 700944</description><a10:updated>2011-11-10T16:18:07-08:00</a10:updated></item><item><guid isPermaLink="false">700942</guid><link>http://connect.microsoft.com/site1168/feedback/details/700942/test</link><author>roiderevez</author><category>Bug</category><title>Test</title><description>Test&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 700942</description><a10:updated>2011-11-10T16:17:52-08:00</a10:updated></item><item><guid isPermaLink="false">700940</guid><link>http://connect.microsoft.com/site1168/feedback/details/700940/test</link><author>roiderevez</author><category>Bug</category><title>Test</title><description>Test&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 700940</description><a10:updated>2011-11-10T16:17:11-08:00</a10:updated></item><item><guid isPermaLink="false">700939</guid><link>http://connect.microsoft.com/site1168/feedback/details/700939/test</link><author>roiderevez</author><category>Bug</category><title>Test</title><description>Test&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 700939</description><a10:updated>2011-11-10T16:16:48-08:00</a10:updated></item><item><guid isPermaLink="false">700938</guid><link>http://connect.microsoft.com/site1168/feedback/details/700938/test</link><author>roiderevez</author><category>Bug</category><title>Test</title><description>Test&lt;BR&gt;&lt;BR&gt;Status: Active, 2 Up-Votes, 0 Down-Votes, 0 validations, 0 workarounds, 1 comment, feedback id: 700938</description><a10:updated>2011-11-10T16:16:39-08:00</a10:updated></item><item><guid isPermaLink="false">700928</guid><link>http://connect.microsoft.com/site1168/feedback/details/700928/testcase</link><author>roiderevez</author><category>Bug</category><title>TestCase</title><description>TestCase&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 700928</description><a10:updated>2011-11-10T16:11:35-08:00</a10:updated></item><item><guid isPermaLink="false">698301</guid><link>http://connect.microsoft.com/site1168/feedback/details/698301/future-plans-for-oauth-2-support-in-wif</link><author>the black labrador</author><category>Bug</category><title>Future plans for OAuth 2 support in WIF</title><description>I have looked at the ACS/OAuth 2 sample and got it to work with no problems but it seems to be a bit inconsistent with the WS-Federation approach used in the existing RTM WIF. In particular, would have expected to have a mirror of the WSFederationAuthenticationModule and SessionAuthenticatonModule from WIF. The sample has an OAuthClient and an OAuthAuthenticationModule, which together seem to be analogous to the WSFAM, but they are configured in the Global.asax and you have to wire events up you...&lt;BR&gt;&lt;BR&gt;Status: Active, 3 Up-Votes, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 698301</description><a10:updated>2011-11-01T02:58:25-07:00</a10:updated></item><item><guid isPermaLink="false">695293</guid><link>http://connect.microsoft.com/site1168/feedback/details/695293/wif-and-saml-2-0</link><author>lcarrion</author><category>Bug</category><title>WIF and SAML 2.0</title><description>We are trying to use this extension in our PoC, this works fine if we used web app, but we have problem when we put our web app in a Azure Web Role, apparently it can’t redirect to our default page in azure emulator. Any help will be very appreciated&lt;BR&gt;&lt;BR&gt;Status: Active, 2 Up-Votes, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 695293</description><a10:updated>2011-10-17T08:58:04-07:00</a10:updated></item><item><guid isPermaLink="false">692663</guid><link>http://connect.microsoft.com/site1168/feedback/details/692663/saml-extension-and-web-parms</link><author>Atef Abdou</author><category>Bug</category><title>SAml extension and Web parms.</title><description>There are several issues with running the extension in a web farm environment. First all url’s that are supposed to be stored  by either the sing-in or sign-out methods do not use a cookie but rather a session based object and thus does not work in a web farm scenario. The single signoutservice also uses a session based object in the form of SessionParticipantStorage .  This means that when attempting to initiate a sps sign-out , no items are found in the storage and thus no SAML request is sent...&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 692663</description><a10:updated>2011-10-02T16:11:33-07:00</a10:updated></item><item><guid isPermaLink="false">690798</guid><link>http://connect.microsoft.com/site1168/feedback/details/690798/honor-saml2protocolserializer-null-ctor-or-option-to-avoid-automatic-signaturevalidation</link><author>Calvin Charles</author><category>Bug</category><title>honor Saml2ProtocolSerializer(null) ctor or option to avoid automatic SignatureValidation</title><description>Even after passing the signatureTokenResolver as null (to indicate signatures should not be validated) still the serializer.ReadMessage(XmlReader) throws SignatureVerificationFailedException. It seems like Saml2SecurityTokenHandler.ReadAssertion calls reader3.TryReadSignature(); which causing EnvelopedSignatureReader.ResolveSigningCredentials() call on EnvelopedSignatureReader.OnEndOfRootElement().  &lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 690798</description><a10:updated>2011-09-26T00:05:28-07:00</a10:updated></item><item><guid isPermaLink="false">690346</guid><link>http://connect.microsoft.com/site1168/feedback/details/690346/error-when-adding-sts-reference-in-german-visual-studio-2010</link><author>patorgjep</author><category>Bug</category><title>Error when adding STS-Reference in German Visual Studio 2010</title><description>In the German Version of Visual Studio 2010 I got an error message when I want to add a STS reference. After selecting "New STS project..." on the second page of the "Administrator: Federation Utility"-wizard and finishing it, i got the error message "HRESULT: 0x80070002" (a file-not-found execption). This problem is caused on all german versions of Visual Studio 2010 in our company, but it works fine with the english Visual Studios. Other users describe the same problem in this discussion: 
ht...&lt;BR&gt;&lt;BR&gt;Status: Active, 3 Up-Votes, 0 Down-Votes, 2 validations, 0 workarounds, 1 comment, feedback id: 690346</description><a10:updated>2011-09-23T00:13:18-07:00</a10:updated></item><item><guid isPermaLink="false">685692</guid><link>http://connect.microsoft.com/site1168/feedback/details/685692/identity-developer-training-kit-for-visual-studio-2010-out-of-date</link><author>Marco Kroonwijk</author><category>Bug</category><title>Identity Developer training kit for Visual Studio 2010 out of date</title><description>Just want to put a remark that the Identity Developer training kit for Visual Studio 2010 is out of date. This can give problems with the labs. For example, I had the following problem reported during EXERCISE 2: ACCEPTING TOKENS FROM AN ACTIVE DIRECTORY FEDERATION SERVICES (ADFS) STS:

"The server certificate with name 'CN=ip-sts-01.federatedidentity.net' failed identity verification because its thumbprint ('DE74CFE7D20E8DC2B6E6E700E4D2A940CB08B268') does not match the one specified in the en...&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 1 workaround, 0 comments, feedback id: 685692</description><a10:updated>2011-08-25T14:22:10-07:00</a10:updated></item><item><guid isPermaLink="false">675166</guid><link>http://connect.microsoft.com/site1168/feedback/details/675166/id6018-digest-verification-failed-for-reference-when-adding-condition-element-to-a-saml2-assertion-conditions</link><author>robert411</author><category>Bug</category><title>"ID6018: Digest verification failed for reference" when adding &lt;Condition&gt; element to a SAML2 assertion &lt;Conditions&gt;.</title><description>We have a requirement to create a SAML 2 assertion that should add a &lt;Delegate&gt; element to the assertion's &lt;Conditions&gt; element. This is part of a federated identity scenario with a WIF based custom STS. A custom Saml2SecurityTokenHandler was added to the STS and the WriteConditions() method was overriden to add the &lt;Delegate&gt; element.

This is an example of the assertion that results:

&lt;Assertion wsu:Id="_8723586f-db82-45c4-93e8-b2e357aacbcf" 
            ID="_8723586f-db82-45c4-93e8-b2e35...&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 0 comments, feedback id: 675166</description><a10:updated>2011-06-13T05:35:10-07:00</a10:updated></item><item><guid isPermaLink="false">672204</guid><link>http://connect.microsoft.com/site1168/feedback/details/672204/acs-oauth-sample</link><author>vu1garis</author><category>Bug</category><title>ACS OAuth sample</title><description>I am trying to implement passive federation with ACS and Outh and this sample comes tantalisingly close to demonstrating how to do this. What I would like to accomplish is as follows...

1. Client tries to access protected resource
2. Client is routed to ACS to choose a passive identity provider (IP)
3. Client picks proprietary IP-STS or Google etc..
4. Client authenticates with IP
5. IP redirects to ACS where claims are transformed.
6. ACS relying party (configured for SWT) returns an OAuth acc...&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 2 workarounds, 0 comments, feedback id: 672204</description><a10:updated>2011-06-01T08:15:49-07:00</a10:updated></item><item><guid isPermaLink="false">670013</guid><link>http://connect.microsoft.com/site1168/feedback/details/670013/signature-signing-method-in-the-idp-metadata-not-used</link><author>LeonGrave</author><category>Bug</category><title>Signature signing method in the IdP metadata not used</title><description>I'm using the SAML2.0 Protocol extension in a Proof of Concept to connect with an ASP.net web application frontend to a Ping Federate IdP. The metadata from Ping Federate contains an XMLDSIG element which describes which signing algoritm the IdP is using.

In my case that is SHA-1, but it seems to be ignored, because when I turn on verbose logging for WIF, I notice that the saml message contains a SHA-256 signature. When I change the setting to SHA-256 in Ping Federate everything works fine, but...&lt;BR&gt;&lt;BR&gt;Status: Active, 4 Up-Votes, 0 Down-Votes, 1 validation, 2 workarounds, 3 comments, feedback id: 670013</description><a10:updated>2011-05-23T12:08:17-07:00</a10:updated></item><item><guid isPermaLink="false">666314</guid><link>http://connect.microsoft.com/site1168/feedback/details/666314/wif-implementation-for-sharepoint-fba-anonymous-portal-scenario</link><author>Ali Butt</author><category>Bug</category><title>WIF implementation for Sharepoint FBA anonymous portal scenario.</title><description>Deployed a SharePoint 2007 portal with FBA having annonymous enabled for complete site. The portal works fine with this configuration. 

Now if you try to integrate the Identity model as provided by WIF for authentication then the anonymous user cannot acces the portal, user is simply denied access to the portal

Cause: Anonymous user is not assigned any identity object, as opposed to any other, lets say FBA, model in which anonymous user is assigned an identity object.&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 1 comment, feedback id: 666314</description><a10:updated>2011-05-02T20:35:27-07:00</a10:updated></item><item><guid isPermaLink="false">663654</guid><link>http://connect.microsoft.com/site1168/feedback/details/663654/wif-cannot-handle-identity-from-java-client</link><author>YOYAN</author><category>Bug</category><title>WIF cannot handle Identity from Java Client</title><description>When Java client (Metro 2.1) sends a token request with &lt;identity&gt; to a WIF STS, it returns a HTTP 500. Please see detail message in JavaClientMessages.txt. 

Comparing the messages sent from C# client (the forth Message Log Trace in PingService_Message_Client_DoubleEncryption.svclog), &lt;identity&gt; element is different from Java message. Seem that WIF cannot understand &lt;identity&gt; sent by Java client.

I can be reached at yoyan@microsoft.com if you need more details.&lt;BR&gt;&lt;BR&gt;Status: Active, 1 Up-Vote, 0 Down-Votes, 0 validations, 1 workaround, 0 comments, feedback id: 663654</description><a10:updated>2011-04-20T12:17:51-07:00</a10:updated></item><item><guid isPermaLink="false">657328</guid><link>http://connect.microsoft.com/site1168/feedback/details/657328/http-status-400-code-when-trying-to-get-refresh-tokens</link><author>Tony Lambert1</author><category>Bug</category><title>HTTP Status 400 Code When Trying to get Refresh Tokens</title><description>I've attempted to configure a few different ACS v2 subscriptions with no success getting refresh tokens to work. As a work-around we can just get a new authorization code/access token, but that's not ideal and shouldn't be necessary. I'm not entirely sure how to go about troubleshooting this as the ACS v2 is a large black box. I've read over the OAuth2 draft10 spec many times at this point and believe that the data that is going to the ACS is correct. All the other calls are working properly.. I...&lt;BR&gt;&lt;BR&gt;Status: Active, 4 Up-Votes, 0 Down-Votes, 2 validations, 0 workarounds, 2 comments, feedback id: 657328</description><a10:updated>2011-04-04T21:14:20-07:00</a10:updated></item><item><guid isPermaLink="false">650340</guid><link>http://connect.microsoft.com/site1168/feedback/details/650340/adfs-server-fails-to-authenticate-while-trying-to-acess-from-internet</link><author>Jithendra Balakrishnan</author><category>Bug</category><title>ADFS Server fails to authenticate while trying to acess from Internet</title><description>We've a publicly hosted ADFS Server which we're using for authenticating enterprise users to access Azure applications.  The authentication works well while trying to access the azure portal from Intranet and everything is smooth.  But when accessed over Internet, the user continuously gets the windows authentication prompt but even after entering the right credentials, the prompt stays on.

We're using a vanilla install of ADFS 2.0 that authenticates against company AD store. The issue is preve...&lt;BR&gt;&lt;BR&gt;Status: Active, 3 Up-Votes, 0 Down-Votes, 2 validations, 0 workarounds, 3 comments, feedback id: 650340</description><a10:updated>2011-03-09T02:30:57-08:00</a10:updated></item><item><guid isPermaLink="false">644697</guid><link>http://connect.microsoft.com/site1168/feedback/details/644697/windows</link><author>skeleton red</author><category>Bug</category><title>windows</title><description>some time it works&lt;BR&gt;&lt;BR&gt;Status: Closed, Resolution: Not Reproducible, 1 Up-Vote, 0 Down-Votes, 0 validations, 0 workarounds, 1 comment, feedback id: 644697</description><a10:updated>2011-02-16T17:21:16-08:00</a10:updated></item><item><guid isPermaLink="false">639424</guid><link>http://connect.microsoft.com/site1168/feedback/details/639424/windows-7</link><author>Karthik Babu</author><category>Bug</category><title>Windows 7 </title><description>The snipping tool in windows 7 saves images with an uppercase extension. This is against convention and should be corrected.

&lt;BR&gt;&lt;BR&gt;Status: Closed, Resolution: External, 2 Up-Votes, 2 Down-Votes, 0 validations, 0 workarounds, 1 comment, feedback id: 639424</description><a10:updated>2011-01-27T23:11:33-08:00</a10:updated></item></channel></rss>