Attribute query with qualified principal name

IAM David Bantz dabantz at alaska.edu
Mon Feb 9 17:46:20 EST 2015


Yes, SAML2.  For some time I could not understand why the vendor insisted
they received no attributes in my SAML, when my outgoing SAML assertion
(POST) clearly contained them.  They were not forthcomming, just repeating
that they received no attributes; I finally realized they disregard the
attributes, just consuming the authN portion, then use SOAP/AttributeQuery
to ask for attributes.  I can't explain why they don't consume the
attributes in the first SAML response; I suppose it might reflect
sequential and/or independent deployment of the two uses of SAML.

On Mon, Feb 9, 2015 at 12:39 PM, Tom Scavo <trscavo at gmail.com> wrote:

> On Mon, Feb 9, 2015 at 2:39 PM, IAM David Bantz <dabantz at alaska.edu>
> wrote:
> >
> > This is the first and only attribute query I've encountered; is there an
> > obvious way to configure the IdP to successfully return attributes?
>
> David, is this SAML2? Are you pushing attributes on the front channel?
> If so, why does the vendor need to query?
>
> Tom
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150209/a74f2df4/attachment.html 


More information about the users mailing list