No attributes are getting passed to SP from my IdP

Peter Schober peter.schober at univie.ac.at
Mon Mar 18 09:21:02 EDT 2013


* lalithj <j_lalith at hotmail.com> [2013-03-18 14:07]:
> Our current production IdP is integrated with a federation, basically IdP
> was installed with their instructions, we do pass attributes to various SPs
> listed in federation Meta data file,
> My concern is, at this stage, we dont have any filter policies, and also no
> uApprove plugin as demonstrated in the link, but got the uApprove
> functionality though

The Shibboleth IdP does not have "uApprove functionality" -- unless
you additionally install and configure uApprove. Or possibly use
someone elses modified distribution of the software that already
includes uApprove.
Either way: The IdP does not send out data unless you told it to.

If you want to find out why the IdP released attributes look at your
idp-process.log at DEBUG level or start by giving specific technical
information regarding your configuration, how you determined you have
"uApprove functionality" with the Shibboleth IdP without using
uApprove, etc.pp.

> So curious to know, how our attributes are passed to each SP in the
> federation, without either filter policy and uApprove plugin,

I already said that's not possible. Even with the uApprove plugin
installed you'll need rules in your attribute filter to cause it to
release data. The plugin only gives one additional condition to check,
namely the presence of requested attributes in metadata. (This is
clearly shown in document at the URL I already sent.)

> What am trying right now is, in addition to the current federation
> integration, we got another new SP (seperate/individual) needs to
> link with our IdP, I just wanted to standardize how we pass
> attributes to these entities (federation or individual SP)

You'd need to find out how data leaves your IdP now, as you seem to
have no idea. Which is not a good thing, from a data protection point
of view.
-peter


More information about the users mailing list