Error When Using University's Idp
IAM David Bantz
dabantz at alaska.edu
Fri Jun 26 21:01:28 EDT 2015
Doesn't the reported SSL failure indicate a failure of the SOAP attribute
query before attribute release even comes into play? If you (that is, the
SP) can't talk to the IdP end point, seems no Shibboleth configuration is
going to get attributes from the IdP to the SP. Or am I totally misreading
the reported errors in Antelmo's post?
log snippet:
> ... SSL protocol error...unable to obtain a SAML response
and curl result:
> * NSS error -5961
> * Closing connection #0
> * SSL connect error
> curl: (35) SSL connect error
David Bantz
U Alaska IAM
On Fri, Jun 26, 2015 at 4:30 PM, Antelmo Aguilar <Antelmo.Aguilar.17 at nd.edu>
wrote:
> Hi Nate and Scott,
>
> The staff member that manages the Idp tells me that the attributes are
> released during the assertion. Also, as far as I can tell, the sp is not
> discarding anything from looking at the logs. Do you guys know how I can
> possibly debug this further? I have been searching online for a way to
> solve this with no success.
>
> Thanks,
> Antelmo
>
>
> On Friday, June 26, 2015, Nate Klingenstein <ndk at internet2.edu> wrote:
>
>> Top Posting here
>>
>> Semt frim mt iPone
>>
>> On Jun 26, 2015, at 14:49, "Antelmo Aguilar" <Antelmo.Aguilar.17 at nd.edu>
>> wrote:
>>
>> Hi Scott and Nate,
>>
>> I believe the issue is on Idp side. I compared the logs using Testshib
>> Idp and the University's Idp and it seems that the University does not
>> include the attributes in the assertion.
>>
>>
>> Probably different for different SP's. Likely different metadata too.
>>
>> I am currently waiting on the staff that manages the Idp to see what
>> he says, but I think with both of your suggestions, we can figure out a
>> solution.
>>
>> Will post back to let you guys know how it went.
>>
>>
>> Thank you.
>>
>> Thanks!
>> Antelmo
>>
>> On Fri, Jun 26, 2015 at 2:58 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>>
>>> > I have been working with one of the staff at the university that is in
>>> charge of
>>> > the Idp and he said that he is releasing the eppn attribute to my
>>> Shibboleth
>>> > SP.
>>>
>>> Then either your SP is using the wrong entityID, there's a Scope issue
>>> with the IdP's metadata vs. what they're putting in the EPPN, as Nate
>>> mentioned, or he's incorrect.
>>>
>>> > If there is no reason to be relying on queries to get them, what other
>>> > mechanism is there for him to release the eppn attribute to me?
>>>
>>> The normal way, including them in the original assertion.
>>>
>>> -- Scott
>>>
>>>
>>> --
>>> To unsubscribe from this list send an email to
>>> users-unsubscribe at shibboleth.net
>>>
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150626/efde2c0a/attachment-0001.html>
More information about the users
mailing list