scoped NameID SAML subject

David Bantz dabantz at alaska.edu
Fri Aug 29 18:26:26 EDT 2014


To tie up this thread, I was able to “build” and attribute syntactically identical to ePPN
that is released as the domain-qualified NameID in the Subject of the SAML assertion using
the definition below.  I’m not proud of it, but it seems to do the job.

<!— Create NameID like ePPN for the SAML Subject -->
<resolver:AttributeDefinition xmlns="urn:mace:shibboleth:2.0:resolver:ad" 
                              xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
                              xmlns:resolver="urn:mace:shibboleth:2.0:resolver" 
                              id="oktanameid" xsi:type="Script" 
                              sourceAttributeID="UASystemID">
	<resolver:Dependency ref="myLDAP"/>
	<resolver:AttributeEncoder xmlns="urn:mace:shibboleth:2.0:attribute:encoder" 
	                           xsi:type="SAML2StringNameID" 
	                           nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"/>
	<Script><![CDATA[
        importPackage(Packages.edu.internet2.middleware.shibboleth.common.attribute.provider);
        importPackage(Packages.org.slf4j);

        if (null == oktanameid) {oktanameid = new BasicAttribute("oktanameid");}
        oktausername = UASystemID.getValues().get(0);
        oktanameid.getValues().add(oktausername + "@alaska.edu");

        ]]></Script>
</resolver:AttributeDefinition>

On Thu, 28 Aug 2014, at 13:53 , Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 8/28/14, 5:48 PM, "David Bantz" <dabantz at alaska.edu> wrote:
> 
>> Attempting to build a NameID in the SAML subject to meet a vendor requirement.
>> The following uses and inserts the right identifier, but despite being based on ePPN, 
>> appears in the SAML assertion subject un-scoped: If ePPN is george at my.domain, this 
>> uses the NameID of george in subject portion of the SAML.  To meet vendor requirement,
>> I need the scoped value george at my.domaim.  Is there a simple way to do that?
>> 
>> <!-- Okta requires something like ePPN in the SAML Subject -->
>> <resolver:AttributeDefinition
>>        id="oktanameid"
>>        xsi:type="Simple"
>>        xmlns="urn:mace:shibboleth:2.0:resolver:ad"
>>        sourceAttributeID="eduPersonPrincipalName"
>>        xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
>>        xmlns:resolver="urn:mace:shibboleth:2.0:resolver">
>>        <resolver:Dependency ref="myLDAP" />
>>        <resolver:Dependency ref="eduPersonPrincipalName" />
>>        <resolver:AttributeEncoder
>>          xsi:type="SAML2StringNameID"
>>          xmlns="urn:mace:shibboleth:2.0:attribute:encoder"
>>          nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" />
>>        <resolver:AttributeEncoder
>>          xsi:type="SAML2String"
>>          xmlns="urn:mace:shibboleth:2.0:attribute:encoder"
>>          name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6"
>>          friendlyName="username" />
>>     </resolver:AttributeDefinition>

> 
> Not simple, you'd have to get an attribute defined that's string-valued
> with both parts included, and attach the encoder to that. Basically what
> you'd do with mail.
> 
> I fixed this in v3 when the new portion of the IdP is used to generate
> NameIDs instead of the resolver.
> 
> -- Scott
> 
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140829/3b1ae692/attachment.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140829/3b1ae692/attachment.bin 


More information about the users mailing list