Need help with canonicalization and attribute resolver in a mutual auth scenario.

Johan Åkerstrøm Johan.Akerstrom at skill.no
Tue Jul 14 12:00:10 EDT 2015


Hello,

I've setup Shibboleth with a single relying party and enabled mutual SSL auth in underlying tomcat.
I have configured idp.authn.flows=X509 and managed to get mutual auth working fine. I have also switched off encryption of assertions and NameIDs in relying-party.xml so that I can trace my SAML request in FireFox SSO Tracer.

In the SSO tracer I see  no NameID or other attributes. So to my questions....

How do I copy the CN of the subject from the x509 certificate into NameID?

How do I use the whole subject (which corresponds to an LDAP distinguished name) from the certificate to lookup other attributes or group memberships in our LDAP directory?

I assume I have to work with subject-c14n.xml, x500-subhect-c14n-config.xml and attribute-resolver.xml but hitting a brick wall at the moment. Anyone who can shed some light on this for me?

Regards Johan



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150714/71d21a4f/attachment.html>


More information about the users mailing list