<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">My product has supported Office 365 authentication via Shibboleth SAML2 integration for several years but a recent regression testing exposed that this feature is not working.
<br>
<br>
The configuration is the same as in previous releases but I did notice the principle being returned
<br>
<br>
<o:p></o:p></p>
<p class="MsoNormal">filter = (uid=rdeWOox+N8Gc626Gq/ZXarrUzjM=)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">My question starts with this userid being returned from Microsoft – should the userid be encrypted and if the userid is encrypted and is failing LDAP lookup because of that would it translate into no viable attribute being releasable ?
<br>
<br>
<o:p></o:p></p>
<p class="MsoNormal">in the filter template inside attribute-resolver.xml<o:p></o:p></p>
<p class="MsoNormal"><dc:FilterTemplate><o:p></o:p></p>
<p class="MsoNormal">            <![CDATA[<o:p></o:p></p>
<p class="MsoNormal">                (uid=$requestContext.principalName)<o:p></o:p></p>
<p class="MsoNormal">            ]]><o:p></o:p></p>
<p class="MsoNormal">        </dc:FilterTemplate><o:p></o:p></p>
<p class="MsoNormal">---------------------------------------------<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">09:18:18.656 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:491] - No attribute of principal 'rdeWOox+N8Gc626Gq/ZXarrUzjM=' can be encoded in to a NameIdentifier of required format 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent'
 for relying party 'urn:federation:MicrosoftOnline’<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">with a response of<br>
<saml2p:Status><o:p></o:p></p>
<p class="MsoNormal">      <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder"><o:p></o:p></p>
<p class="MsoNormal">         <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy"/><o:p></o:p></p>
<p class="MsoNormal">      </saml2p:StatusCode><o:p></o:p></p>
<p class="MsoNormal">      <saml2p:StatusMessage>Required NameID format not supported</saml2p:StatusMessage><o:p></o:p></p>
<p class="MsoNormal">   </saml2p:Status><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">fragment from attribute-resolver.xml<o:p></o:p></p>
<p class="MsoNormal"><!-- UserPrincipalName for Windows Azure AD User ID --><o:p></o:p></p>
<p class="MsoNormal"><resolver:AttributeDefinition id="UserId" xsi:type="ad:Simple" sourceAttributeID="mail"><o:p></o:p></p>
<p class="MsoNormal">      <resolver:Dependency ref="myLDAP" /><o:p></o:p></p>
<p class="MsoNormal">      <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="IDPEmail" friendlyName="UserId" /><o:p></o:p></p>
<p class="MsoNormal"></resolver:AttributeDefinition><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial","sans-serif"">Rob MacKay | Architect, Luminis Platform |</span>
<span style="font-size:12.0pt;font-family:"Arial","sans-serif";color:#391651">ellucian</span><span style="font-size:6.0pt;font-family:"Arial","sans-serif";color:#391651">®</span>  |
<span style="font-size:10.0pt;font-family:"Arial","sans-serif"">O:+1.801.257.4247 | M:+1.801.787.0504 |
<a href="http://www.ellucian.com"><span style="color:blue">www.ellucian.com</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Arial","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.0pt;font-family:"Arial","sans-serif"">CONFIDENTIALITY: This email (including any attachments) may contain confidential, proprietary and privileged information, and unauthorized disclosure or use is prohibited. If
 you received this email in error, please notify the sender and delete this email from your system. Thank you.</span><span style="font-size:10.0pt;font-family:"Arial","sans-serif""><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>