Releasing attributes from Active Directory for Office 365

Dennis Casimiro dcasimiro at BORNQUIST.com
Wed Aug 28 15:33:20 EDT 2013


Now I know this is a dumb question...but what is the easiest way to
prove that I am at least properly releasing something, whether it is
encoded or not?

Dennis

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net]
On Behalf Of Kevin P. Foote
Sent: Tuesday, August 27, 2013 9:10 AM
To: Shib Users
Subject: Re: Releasing attributes from Active Directory for Office 365 


On Tue, 27 Aug 2013, Dennis Casimiro wrote:

> I can't seem to figure out or troubleshoot properly how to encode and 
> pass attributes to MicrosoftOnline.
>
>
>
> The WARN error that appears applicable is:
>
>
>
> 08:47:10.342 - WARN
> [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHa
> nd ler:491] - No attribute of principal 'XXXXXX' can be encoded in to 
> a NameIdentifier of required format 
> 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent' for relying 
> party 'urn:federation:MicrosoftOnline'

So with the IdP you can encode any of your resolved attributes into
particular formats for release as the NameId element.

My huntch is you are not encoding anything you are releasing to o365
into the proper NameID format..

So take a look at your release for your o365 RP and then look at what
you have encoded into the format that the o365 RP wants. (hope that made
sense)

<http://cp.mcafee.com/d/1jWVIe3x8i43qb8UsUyCUOMrKrjoppvuoKrjoppvu7cCQS6m
nTC4jqr3bbXMVMSxrqilB6Ea8lz0mrBivbCO5oM5CVkDOVIQsLIAb8FLZvChPUVeZ-LsKyqe
kQuvjohpKqeumKDp55mVEVoVkffGhBrwqrhdECXCXCOsVHkiP34yIKEjAg8lf-pfwrBGMtfr
-5LN2l5zZboc1sd6kY1CG-6xMxesp46V_gQv6SWv6xsxlK5LE2G4V425j_CjU6CSbCzBAS2_
id40bY_ZFa14Qgresp46V_gQgeNGGq812QV6vd40tafSDm9oQgeRyq80MWXaTCy1BNYQg6XC
YjlO

HTH

------
thanks
  kevin.foote
--
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net


More information about the users mailing list