employeeNumber from employeeID in active directory

Jean Robertson jean.robertson at mcgill.ca
Tue Sep 6 20:58:14 BST 2011


I am using a Shib IdP of 2.1.5 vintage.

I need to retreive from MS Active Directory employeeID.

I want to encode it as employeeNumber.

The AD server has been setup to release it to the shib IdP.

I have an attribute-resolver.xml snippet that looks like this:

    <resolver:AttributeDefinition id="employeeNumber"
        xsi:type="Simple" xmlns="urn:mace:shibboleth:2.0:resolver:ad"
        <resolver:Dependency ref="myLDAP" />

        <resolver:AttributeEncoder xsi:type="SAML1String"
            name="urn:mace:dir:attribute-def:employeeNumber" />

        <resolver:AttributeEncoder xsi:type="SAML2String"
            friendlyName="employeeNumber" />

I have debugging turned on.

In the idp-process.log, I see the following:

- Found the following attribute: employeeID=[150998702]

after that, nothing.

No mention of either employeeID or employeeNumber.

I am definitely missing something.

If anyone can point me in the right direction, it would be much appreciated.


Jean Robertson, McGill University (514) 398-8117

More information about the users mailing list