Can't retrieve attributes from ldap

Michael A Grady mgrady at unicon.net
Fri Jan 11 18:49:17 EST 2013


So I take it that your users log in with their harvardeduidnumber as their username? I think that should be  ' harvardeduidnumber=$requestContext.principalName ', although if the logs are showing the username you logged in as what its looking for, then just having "principal" is presumably ok. A subtree search is the default, so you don't actually need to specify that.

Which version of the IdP are you running? What LDAP server?

On Jan 11, 2013, at 5:18 PM, Erdos, Marlena wrote:

> Hi all,
> 
> Apologies if this is "stupid" -- but I could not find an answer by
> googling and reading prior postings on ldap and attribute acquisition.
> 
> I've defined an LDAP data connector -- see below -- in
> attribute-resolver.xml .
> 
> The idp_process.log seems to be telling me that the connection is getting
> made OK  -- or rather, it's not showing an error -- but no attributes
> seem to be returned. (Or rather, I can't tell.  I do know it's not getting
> the ones I'm asking for.  (I have logging for ldap turned up to DEBUG.))
> 
> Here is the clause from attribute-resolver.xml followed by an excerpt from
> the log.  I follow that with the definitions for the attrs I'm seeking
> (where I've only changed
> the name of the dependency ref).
> 
> Note:  I use "harvardeduidnumber" instead of the typical "uid" because
> that's what we do here :-).  This works in a ldap client.  You'll see that
> the value is  a number (1234567) not a name (because that's what we do
> here :-)). (I've replace the real one with 1234567  because I'm not
> supposed to release the real one
> into the wild :-).)
> 
> Note 2:  I tried the search without specifying "ReturnAttributes" and got
> the same result.  I've also specified "mail cn" and got the same result
> (of no attrs seemingly returned).
> 
> Note 3: I'm using ldaps and specifying a port in the ldapURL line.
> 
> Note 4:  The same url, baseDN, creds and filter works in an ldap client --
> with subtree search enabled. It fails if subtree search is not enabled.
> Which is why I try to enable it in the searchScope attribute below.
> 
> 
> Note 5: I do not have access to the ldap server logs.  (I'm attempting to
> get that changed but it's not clear that it will be.)
> 
>    <resolver:DataConnector id="HULDAP" xsi:type="dc:LDAPDirectory"
>        ldapURL="ldaps://hu-ldap-test.harvard.edu:636"
>        baseDN="ou=people,o=Harvard University
> Core,dc=huid,dc=harvard,dc=edu"
>        principal ="uid=shibbidp,ou=applications,o=Harvard University
> Core,dc=huid,dc=harvard,dc=edu"
>        principalCredential="<removed>"
>         searchScope="SUBTREE"
>         lowercaseAttributeNames="true">
>        <dc:FilterTemplate>
>            <![CDATA[
>                (harvardeduidnumber=$requestContext.principal)
>            ]]>
>        </dc:FilterTemplate>
>    <dc:ReturnAttributes>*</dc:ReturnAttributes>
> 
> 
> 
> 
> 18:02:23.383 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.Shi
> bbolethAttributeResolver:119] - shibboleth.AttributeResolver resolving
> attributes for principal 1234567
> 18:02:23.385 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.Shi
> bbolethAttributeResolver:275] - Specific attributes for principal 1234567
> were not requested, resolving all attributes.
> 18:02:23.385 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.Shi
> bbolethAttributeResolver:314] - Resolving attribute commonName for
> principal 1234567
> 18:02:23.389 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.Shi
> bbolethAttributeResolver:354] - Resolving data connector HULDAP for
> principal 1234567
> 18:02:23.474 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.dat
> aConnector.LdapDataConnector:308] - Search filter:
> (harvardeduidnumber=$requestContext.principal)
> 18:02:23.474 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.dat
> aConnector.LdapDataConnector:363] - LDAP data connector HULDAP -
> Retrieving attributes from LDAP
> 18:02:23.475 - DEBUG
> [edu.vt.middleware.ldap.handler.DefaultConnectionHandler:74] - Bind with
> the following parameters:
> 18:02:23.475 - DEBUG
> [edu.vt.middleware.ldap.handler.DefaultConnectionHandler:75] -   authtype
> = simple
> 18:02:23.475 - DEBUG
> [edu.vt.middleware.ldap.handler.DefaultConnectionHandler:76] -   dn =
> uid=shibbidp,ou=applications,o=Harvard University
> Core,dc=huid,dc=harvard,dc=edu
> 18:02:23.480 - DEBUG
> [edu.vt.middleware.ldap.handler.DefaultConnectionHandler:83] -
> credential = <suppressed>
> 18:02:23.492 - DEBUG
> [edu.vt.middleware.ldap.handler.DefaultConnectionHandler:128] - Set
> hostname verifier for ldaps
> 18:02:23.501 - DEBUG [edu.vt.middleware.ldap.ssl.AggregateTrustManager:75]
> - invoking checkServerTrusted for
> sun.security.ssl.X509TrustManagerImpl at b7cf28b
> 18:02:23.503 - DEBUG [edu.vt.middleware.ldap.ssl.AggregateTrustManager:75]
> - invoking checkServerTrusted for
> edu.vt.middleware.ldap.ssl.HostnameVerifyingTrustManager at 5e65ab77
> 18:02:23.504 - DEBUG
> [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:122] - Verify with the
> following parameters:
> 18:02:23.504 - DEBUG
> [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:123] -   hostname =
> hu-ldap-test.harvard.edu
> 18:02:23.504 - DEBUG
> [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:124] -   cert =
> CN=hu-ldap-test.harvard.edu, OU=President and Fellows of Harvard College,
> O=Harvard University, L=Cambridge, ST=Massachusetts, C=US,
> SERIALNUMBER=abfuu/nLytNOUQX17DPc2ea/ijJIvQUu
> 18:02:23.507 - DEBUG
> [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:197] - verifyDNS using
> subjectAltNames = [hu-ldap-test.harvard.edu]
> 18:02:23.507 - DEBUG
> [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:205] - verifyDNS found
> hostname match: hu-ldap-test.harvard.edu
> 18:02:23.734 - DEBUG [edu.vt.middleware.ldap.Ldap:193] - Search with the
> following parameters:
> 18:02:23.735 - DEBUG [edu.vt.middleware.ldap.Ldap:194] -   dn =
> ou=people,o=Harvard University Core,dc=huid,dc=harvard,dc=edu
> 18:02:23.735 - DEBUG [edu.vt.middleware.ldap.Ldap:195] -   filter =
> (harvardeduidnumber=$requestContext.principal)
> 18:02:23.738 - DEBUG [edu.vt.middleware.ldap.Ldap:196] -   filterArgs = []
> 18:02:23.738 - DEBUG [edu.vt.middleware.ldap.Ldap:197] -   searchControls
> = javax.naming.directory.SearchControls at 32a88bc2
> 18:02:23.738 - DEBUG [edu.vt.middleware.ldap.Ldap:198] -   handler =
> [edu.vt.middleware.ldap.handler.FqdnSearchResultHandler at 576f8789,
> edu.vt.middleware.ldap.handler.EntryDnSearchResultHandler at 5b2b6037,
> edu.vt.middleware.ldap.handler.CaseChangeSearchResultHandler at 7cb9e9a3,
> edu.vt.middleware.ldap.handler.BinarySearchResultHandler at 119a0c4e]
> 18:02:23.758 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.Shi
> bbolethAttributeResolver:336] - Resolved attribute commonName containing 0
> values
> 18:02:23.759 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.Shi
> bbolethAttributeResolver:314] - Resolving attribute email for principal
> 1234567
> 18:02:23.759 - DEBUG
> [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.Shi
> bbolethAttributeResolver:336] - Resolved attribute email containing 0
> values
> 18:02:23.759 - 
> 
> 
> 
> 
>   <resolver:AttributeDefinition xsi:type="ad:Simple" id="email"
> sourceAttributeID="mail">
>        <resolver:Dependency ref="HULDAP" />
>        <resolver:AttributeEncoder xsi:type="enc:SAML1String"
> name="urn:mace:dir:attribute-def:mail" />
>        <resolver:AttributeEncoder xsi:type="enc:SAML2String"
> name="urn:oid:0.9.2342.19200300.100.1.3" friendlyName="mail" />
>    </resolver:AttributeDefinition>
> 
> 
> 
> <resolver:AttributeDefinition xsi:type="ad:Simple" id="commonName"
> sourceAttributeID="cn">
>        <resolver:Dependency ref="HULDAP" />
>        <resolver:AttributeEncoder xsi:type="enc:SAML1String"
> name="urn:mace:dir:attribute-def:cn" />
>        <resolver:AttributeEncoder xsi:type="enc:SAML2String"
> name="urn:oid:2.5.4.3" friendlyName="cn" />
>    </resolver:AttributeDefinition>
> 
> 
> 
> Thanks so much for whatever help you can provide.  (I'd actually be
> delighted if I'd made a "dumb user error" that could have a quick fix.)
> 
> --Marlena Erdos
> Harvard University Information Technology
> Innovation & Architecture
> Senior Technologist
> (Office) +1 (617) 495-9852
> (Mobile) +1 (617) 872-9736
> Holyoke Center,  Room 762
> 1350 Mass Ave 
> Cambridge, MA 02138
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.



More information about the users mailing list