How to get my SP to send a specific name ID format ?
Pete Newing
pn at flexeyetech.com
Fri Jun 22 12:13:00 BST 2012
All,
I've installed a new 2.4.3 SP and, following the wiki instructions,
successfully tested it against TestShib Two.
I've now changed this to point to a clients commercial IdP and found an
issue with authentication.
The client is telling me that I need to provide a specific name ID format
in my SAML auth request.
I've had a look in the archives and the wiki and it looks like I need an
AuthnRequest.
But I can't see where I would put this in my shibboleth2.xml file?
Could someone point me in the right direction please... Thanks in advance...
Here's a sanitized copy of the file....
<SPConfig xmlns="urn:mace:shibboleth:2.0:native:sp:config"
xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
clockSkew="1800">
<!-- Windows RequestMapper -->
<!-- The RequestMap defines portions of the webspace to protect;
mysp.example.com/ here. -->
<!--
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRequestMap -->
<RequestMapper type="Native">
<RequestMap applicationId="default">
<Host name="mysp.example.com">
<Path name="/" authType="shibboleth" requireSession="true"/>
</Host>
</RequestMap>
</RequestMapper>
<!-- The entityID is the name made for this SP. -->
<ApplicationDefaults entityID="https://mysp.example.com/shibboleth-sp"
REMOTE_USER="eppn persistent-id targeted-id">
<!-- You should use secure cookies if at all possible. See
cookieProps in this Wiki article. -->
<!--
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions -->
<Sessions lifetime="28800" timeout="3600" checkAddress="false"
relayState="ss:mem" handlerSSL="false">
<!-- Triggers a login request directly to the myTargetIdP IdP.
-->
<!--
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPServiceSSO -->
<SSO entityID="https://myTargetIdP.com/saml20">
SAML2 SAML1
</SSO>
<!-- SAML and local-only logout. -->
<!--
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPServiceLogout-->
<Logout>SAML2 Local</Logout>
<!--
Handlers allow you to interact with the SP and gather more
information. Try them out!
Attribute values received by the SP through SAML will be
visible at:
http://mysp.example.com/Shibboleth.sso/Session
-->
<!-- Extension service that generates "approximate" metadata
based on SP configuration. -->
<Handler type="MetadataGenerator" Location="/Metadata"
signing="false"/>
<!-- Status reporting service. -->
<Handler type="Status" Location="/Status" acl="127.0.0.1"/>
<!-- Session diagnostic service. -->
<Handler type="Session" Location="/Session"
showAttributeValues="true"/>
<!-- JSON feed of discovery information. -->
<Handler type="DiscoveryFeed" Location="/DiscoFeed"/>
</Sessions>
<!-- Error pages to display to yourself if something goes horribly
wrong. -->
<Errors supportContact="me at my-email.com" logoLocation="logo.jpg"
styleSheet="main.css"/>
<!-- Loads and trusts a metadata file that describes MyTargetIdP
IdP and how to communicate with it. -->
<MetadataProvider type="XML" file="/etc/shibboleth/myTagetIdP.xml"/>
<!-- Attribute and trust options you shouldn't need to change. -->
<AttributeExtractor type="XML" validate="true"
path="attribute-map.xml"/>
<AttributeResolver type="Query" subjectMatch="true"/>
<AttributeFilter type="XML" validate="true"
path="attribute-policy.xml"/>
<!-- Your SP generated these credentials. They're used to talk to
IdP's. -->
<CredentialResolver type="File" key="sp-key.pem"
certificate="sp-cert.pem"/>
</ApplicationDefaults>
<!-- Security policies you shouldn't change unless you know what you're
doing. -->
<SecurityPolicyProvider type="XML" validate="true"
path="security-policy.xml"/>
<!-- Low-level configuration about protocols and bindings available for
use. -->
<ProtocolProvider type="XML" validate="true" reloadChanges="false"
path="protocols.xml"/>
</SPConfig>
Regards, Pete
*Peter L.K. Newing, CISSP, CISA, ITIL V3 Foundation, ISO 27001 Lead Auditor*
*Director of **Product Management*
* *
UK Mobile: +44 7545 073 406
US Mobile: +1 424 789 0265
Flexeye Technology Ltd
This email and any attachments are confidential and may be privileged. If
you have received it in error, do not read it, copy it, forward it,
disclose its contents or use it for any purpose. Please notify us
immediately and then delete it. Any views or opinions expressed are solely
those of the author and not necessarily those of Flexeye Technology Ltd.
This email was sent from Flexeye Technology Limited, Hays House, Millmead,
Guildford GU2 4HJ. Registered Office: Wey Court West, Union Road, Farnham,
Surrey GU9 7PT United Kingdom. Registered in England No 4852559. VAT no GB
821 3432 66A
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120622/b314092f/attachment.html
More information about the users
mailing list