Attributes not showing in testshib
Chad La Joie
lajoie at shibboleth.net
Tue Oct 18 11:43:34 BST 2011
There isn't anything can you fix. The TestShib SP is only configured to
accept common, standard attributes. What you're passing it are not
standard-based attributes and so they aren't going to be accepted by the SP.
On 10/18/11 6:40 AM, Jan Keirse wrote:
> Hello,
>
> I'm trying to configure a Shibboleth IdP but I'm running in to a problem
> and seem unable to find what's wrong.
> I've configured the IdP so that it returns the following XML to testshib:
>
> <?xml version="1.0" encoding="UTF-8"?><saml2:Assertion
> xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
> ID="_cb21f85254ab0b676a8d4655f12f61a2"
> IssueInstant="2011-10-18T10:25:35.901Z" Version="2.0">
> <saml2:Issuer
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://pc1023.tvh.com/idp/shibboleth</saml2:Issuer>
> <saml2:Subject>
> <saml2:NameID
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
> NameQualifier="https://pc1023.tvh.com/idp/shibboleth"
> SPNameQualifier="https://sp.testshib.org/shibboleth-sp">_5967559cd46d6fbc276fce070700aed2</saml2:NameID>
> <saml2:SubjectConfirmation
> Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
> <saml2:SubjectConfirmationData Address="172.16.104.117"
> InResponseTo="_3f469680b71ec8497be41e5f7f2f9305"
> NotOnOrAfter="2011-10-18T10:30:35.901Z"
> Recipient="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"/>
> </saml2:SubjectConfirmation>
> </saml2:Subject>
> <saml2:Conditions NotBefore="2011-10-18T10:25:35.901Z"
> NotOnOrAfter="2011-10-18T10:30:35.901Z">
> <saml2:AudienceRestriction>
> <saml2:Audience>https://sp.testshib.org/shibboleth-sp</saml2:Audience>
> </saml2:AudienceRestriction>
> </saml2:Conditions>
> <saml2:AuthnStatement AuthnInstant="2011-10-18T10:25:35.792Z"
> SessionIndex="a7141213146f6707265fefd384c117979f669d6f9493fe6993bd4ec15ee07a81">
> <saml2:SubjectLocality Address="172.16.104.117"/>
> <saml2:AuthnContext>
>
> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
> </saml2:AuthnContext>
> </saml2:AuthnStatement>
> <saml2:AttributeStatement>
> <saml2:Attribute FriendlyName="name" Name="name"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
> <saml2:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
> xsi:type="xs:string">Jan Keirse</saml2:AttributeValue>
> </saml2:Attribute>
> <saml2:Attribute FriendlyName="login" Name="login"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
> <saml2:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema"
> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
> xsi:type="xs:string">jankeir</saml2:AttributeValue>
> </saml2:Attribute>
> </saml2:AttributeStatement>
> </saml2:Assertion>
>
> However the https://sp.testshib.org/testing/sample.jsp page does not show
> the attributes after login, it only shows this:
>
> Cache-Control is: max-age=0
> Shib-Session-ID is: _9c426f4482e38cf08c9bac5ff1c81cf4
> Shib-Identity-Provider is: https://pc1023.tvh.com/idp/shibboleth
> Shib-Authentication-Method is:
> urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
> Shib-Authentication-Instant is: 2011-10-18T10:25:35.792Z
> Shib-AuthnContext-Class is:
> urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
> Shib-Assertion-Count is: 01
> transient-id is: _5967559cd46d6fbc276fce070700aed2
> Shib-Application-ID is: default
> Shib-Assertion-01 is:
> http://localhost/Shibboleth.sso/GetAssertion?key=_9c426f4482e38cf08c9bac5ff1c81cf4&ID=_b4a7f17f29e8bfd20852d9c83c232ee0
>
> The testshib shibd.log contains the following after authentication:
>
> 2011-10-18 06:31:24 DEBUG Shibboleth.SSO.SAML2 [7]: extracting issuer from
> SAML 2.0 assertion
> 2011-10-18 06:31:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [7]:
> evaluating message flow policy (replay checking on, expiration 60)
> 2011-10-18 06:31:24 DEBUG XMLTooling.StorageService [7]: inserted record
> (_b4a7f17f29e8bfd20852d9c83c232ee0) in context (MessageFlow)
> 2011-10-18 06:31:24 DEBUG Shibboleth.SSO.SAML2 [7]: SSO profile processing
> completed successfully
> 2011-10-18 06:31:24 DEBUG Shibboleth.SSO.SAML2 [7]: extracting pushed
> attributes...
> 2011-10-18 06:31:24 DEBUG Shibboleth.AttributeDecoder.String [7]: decoding
> SimpleAttribute (transient-id) from SAML 2 NameID with Format
> (urn:oasis:names:tc:SAML:2.0:nameid-format:transient)
> 2011-10-18 06:31:24 INFO Shibboleth.AttributeExtractor.XML [7]: skipping
> unmapped SAML 2.0 Attribute with Name: name,
> Format:urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified
> 2011-10-18 06:31:24 INFO Shibboleth.AttributeExtractor.XML [7]: skipping
> unmapped SAML 2.0 Attribute with Name: login,
> Format:urn:oasis:names:tc:SAML:2.0:attrname-format:basic
> 2011-10-18 06:31:24 DEBUG Shibboleth.AttributeFilter [7]: filtering 1
> attribute(s) from (https://pc1023.tvh.com/idp/shibboleth)
> 2011-10-18 06:31:24 DEBUG Shibboleth.AttributeFilter [7]: applying
> filtering rule(s) for attribute (transient-id) from
> (https://pc1023.tvh.com/idp/shibboleth)
>
> I assume the 'skipping unmapped attribute' is what I should fix, but I
> can't seem to find how.
>
> This is what I use in attribute-resolver.xml for these items:
>
> <resolver:AttributeDefinition xsi:type="ad:Simple" id="name"
> xmlns="urn:mace:shibboleth:2.0:resolver:ad" >
> <resolver:Dependency ref="newLDAP" />
> <resolver:Dependency ref="oldLDAP" />
> <resolver:AttributeEncoder xsi:type="SAML2String"
> xmlns="urn:mace:shibboleth:2.0:attribute:encoder"
> nameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"
> name="name" friendlyName="name" />
> </resolver:AttributeDefinition>
>
>
> Kind Regards,
>
> JAN KEIRSE
> ICT-DEPARTMENT
> Software quality & Systems: Software Engineer
>
> **** DISCLAIMER ****
>
> http://www.tvh.com/newen2/emaildisclaimer/default.html
>
> "This message is delivered to all addressees subject to the conditions
> set forth in the attached disclaimer, which is an integral part of this
> message."
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list