Attributes not showing in testshib

Chad La Joie lajoie at shibboleth.net
Tue Oct 18 11:43:34 BST 2011


There isn't anything can you fix.  The TestShib SP is only configured to
accept common, standard attributes.  What you're passing it are not
standard-based attributes and so they aren't going to be accepted by the SP.

On 10/18/11 6:40 AM, Jan Keirse wrote:
> Hello,
> 
> I'm trying to configure a Shibboleth IdP but I'm running in to a problem 
> and seem unable to find what's wrong. 
> I've configured the IdP so that it returns the following XML to testshib:
> 
> <?xml version="1.0" encoding="UTF-8"?><saml2:Assertion 
> xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" 
> ID="_cb21f85254ab0b676a8d4655f12f61a2" 
> IssueInstant="2011-10-18T10:25:35.901Z" Version="2.0">
>    <saml2:Issuer 
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://pc1023.tvh.com/idp/shibboleth</saml2:Issuer>
>    <saml2:Subject>
>       <saml2:NameID 
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" 
> NameQualifier="https://pc1023.tvh.com/idp/shibboleth" 
> SPNameQualifier="https://sp.testshib.org/shibboleth-sp">_5967559cd46d6fbc276fce070700aed2</saml2:NameID>
>       <saml2:SubjectConfirmation 
> Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
>          <saml2:SubjectConfirmationData Address="172.16.104.117" 
> InResponseTo="_3f469680b71ec8497be41e5f7f2f9305" 
> NotOnOrAfter="2011-10-18T10:30:35.901Z" 
> Recipient="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"/>
>       </saml2:SubjectConfirmation>
>    </saml2:Subject>
>    <saml2:Conditions NotBefore="2011-10-18T10:25:35.901Z" 
> NotOnOrAfter="2011-10-18T10:30:35.901Z">
>       <saml2:AudienceRestriction>
>  <saml2:Audience>https://sp.testshib.org/shibboleth-sp</saml2:Audience>
>       </saml2:AudienceRestriction>
>    </saml2:Conditions>
>    <saml2:AuthnStatement AuthnInstant="2011-10-18T10:25:35.792Z" 
> SessionIndex="a7141213146f6707265fefd384c117979f669d6f9493fe6993bd4ec15ee07a81">
>       <saml2:SubjectLocality Address="172.16.104.117"/>
>       <saml2:AuthnContext>
>  
> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
>       </saml2:AuthnContext>
>    </saml2:AuthnStatement>
>    <saml2:AttributeStatement>
>       <saml2:Attribute FriendlyName="name" Name="name" 
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
>          <saml2:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" 
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
> xsi:type="xs:string">Jan Keirse</saml2:AttributeValue>
>       </saml2:Attribute>
>       <saml2:Attribute FriendlyName="login" Name="login" 
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
>          <saml2:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" 
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
> xsi:type="xs:string">jankeir</saml2:AttributeValue>
>       </saml2:Attribute>
>    </saml2:AttributeStatement>
> </saml2:Assertion>
> 
> However the https://sp.testshib.org/testing/sample.jsp  page does not show 
> the attributes after login, it only shows this:
> 
> Cache-Control is: max-age=0
> Shib-Session-ID is: _9c426f4482e38cf08c9bac5ff1c81cf4
> Shib-Identity-Provider is: https://pc1023.tvh.com/idp/shibboleth
> Shib-Authentication-Method is:
> urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
> Shib-Authentication-Instant is: 2011-10-18T10:25:35.792Z
> Shib-AuthnContext-Class is: 
> urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
> Shib-Assertion-Count is: 01
> transient-id is: _5967559cd46d6fbc276fce070700aed2
> Shib-Application-ID is: default
> Shib-Assertion-01 is: 
> http://localhost/Shibboleth.sso/GetAssertion?key=_9c426f4482e38cf08c9bac5ff1c81cf4&ID=_b4a7f17f29e8bfd20852d9c83c232ee0
> 
> The testshib shibd.log contains the following after authentication: 
> 
> 2011-10-18 06:31:24 DEBUG Shibboleth.SSO.SAML2 [7]: extracting issuer from 
> SAML 2.0 assertion
> 2011-10-18 06:31:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [7]: 
> evaluating message flow policy (replay checking on, expiration 60)
> 2011-10-18 06:31:24 DEBUG XMLTooling.StorageService [7]: inserted record 
> (_b4a7f17f29e8bfd20852d9c83c232ee0) in context (MessageFlow)
> 2011-10-18 06:31:24 DEBUG Shibboleth.SSO.SAML2 [7]: SSO profile processing 
> completed successfully
> 2011-10-18 06:31:24 DEBUG Shibboleth.SSO.SAML2 [7]: extracting pushed 
> attributes...
> 2011-10-18 06:31:24 DEBUG Shibboleth.AttributeDecoder.String [7]: decoding 
> SimpleAttribute (transient-id) from SAML 2 NameID with Format 
> (urn:oasis:names:tc:SAML:2.0:nameid-format:transient)
> 2011-10-18 06:31:24 INFO Shibboleth.AttributeExtractor.XML [7]: skipping 
> unmapped SAML 2.0 Attribute with Name: name, 
> Format:urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified
> 2011-10-18 06:31:24 INFO Shibboleth.AttributeExtractor.XML [7]: skipping 
> unmapped SAML 2.0 Attribute with Name: login, 
> Format:urn:oasis:names:tc:SAML:2.0:attrname-format:basic
> 2011-10-18 06:31:24 DEBUG Shibboleth.AttributeFilter [7]: filtering 1 
> attribute(s) from (https://pc1023.tvh.com/idp/shibboleth)
> 2011-10-18 06:31:24 DEBUG Shibboleth.AttributeFilter [7]: applying 
> filtering rule(s) for attribute (transient-id) from 
> (https://pc1023.tvh.com/idp/shibboleth)
> 
> I assume the 'skipping unmapped attribute' is what I should fix, but I 
> can't seem to find how. 
> 
> This is what I use in attribute-resolver.xml for these items:
> 
> <resolver:AttributeDefinition xsi:type="ad:Simple" id="name" 
> xmlns="urn:mace:shibboleth:2.0:resolver:ad" >
>     <resolver:Dependency ref="newLDAP" />
>     <resolver:Dependency ref="oldLDAP" />
>     <resolver:AttributeEncoder xsi:type="SAML2String" 
> xmlns="urn:mace:shibboleth:2.0:attribute:encoder" 
> nameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"
>                                 name="name" friendlyName="name" />
>   </resolver:AttributeDefinition>
> 
> 
> Kind Regards,
> 
> JAN KEIRSE
> ICT-DEPARTMENT
> Software quality & Systems: Software Engineer
> 
> **** DISCLAIMER ****
> 
> http://www.tvh.com/newen2/emaildisclaimer/default.html 
> 
> "This message is delivered to all addressees subject to the conditions
> set forth in the attached disclaimer, which is an integral part of this
> message."
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list