WebAuthn: Issue with Fido metadata?

Mats Luspa mats.luspa at irf.se
Wed Oct 30 12:45:24 UTC 2024


Yes, it was enough to export it:

<AttributeDefinition id="irfAuthorizedService" xsi:type="Simple" 
xmlns="urn:mace:shibboleth:2.0:resolver">
         <InputDataConnector ref="myLDAP" 
attributeNames="irfAuthorizedService"/>
         <AttributeEncoder xsi:type="SAML2String" 
name="urn:oid:1.3.6.1.4.1.7592.1.1.13" 
friendlyName="irfAuthorizedService" encodeType="false" />
</AttributeDefinition>

/Regards Mats

On 2024-10-30 12:59, Cantor, Scott wrote:
>> You are absolutely correct. irfAuthorizedService is an ldap
>> attribute not resolved.
> Then just export it.
>
>> I have now made a scripted attribute that checks if
>> irfAuthorizedService contains shibAdmin and it works now
> That is doubly overkill.
>
> -- Scott
>   
>
-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: matsl at irf.se
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: https://www.irf.se/pgp/matsl
Digital vcard: https://www.irf.se/vcard/mats.luspa

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5037 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/dev/attachments/20241030/2637f9a3/attachment.p7s>


More information about the dev mailing list