shibboleth authentication with Active Directory UPN

Mauro Minella Mauro.Minella at microsoft.com
Sat Sep 15 13:37:50 EDT 2012


Thanks guys. But can you help understanding why I apparently get different assertions if I get authenticated with flat sAMAccountName or userPrincipalName?
In fact, you told me how to login with both attributes on the shibtest page, and it works if I go straight there, however when the same Shib login page is called by the service provider (in my case, Office365), I'm allowed to use that service provider only if I use the sAMAccountName authentication method. If, instead, I configure login.config to accept the userPrincipalName on the Shibboleth authentication, I'm authenticated on the shib page, but then my service provider says that I'm not authorized to use it.
In other words, it seems that different assertions are released, when I just change the userField setting.

Thanks,

Mauro


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Daniel Fisher
Sent: sabato 15 settembre 2012 04.04
To: Shib Users
Subject: Re: shibboleth authentication with Active Directory UPN

On Fri, Sep 14, 2012 at 9:05 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 9/14/12 8:44 PM, "Mauro Minella" <Mauro.Minella at microsoft.com> wrote:
>
>>Found: I should update it as follows
>
> The userField setting can contain multiple fields to search on, you 
> just separate them with commas.
>

You can also set the filter directly with the userFilter property:
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthUserPass

--Daniel Fisher
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net




More information about the users mailing list