Two AD data connectors issue with Attribute-resolver

Douglas E Engert deengert at gmail.com
Wed Oct 14 20:33:15 EDT 2015


If they are both in the same forest, you could just query the top domain, or use the Global Catalog.



On 10/14/2015 1:08 PM, Colon, Joseph wrote:
> Hello everyone,
>
> I am new to Shibboleth and have finally muddled through installation of IDPv3 on a Windows box and have the IDP configured as described here:
>
> /"Example for two Active Directory Directories with two DN Resolvers for each"/(https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories)
>
> So I have 2 AD domains both in the same forest and when I test against https://sp.testshib.org, I can see that the “ldap-authn-config.xml” is working as expected.  Users from both domains can
> authenticate.
>
> Now I am trying to set up the “attribute-resolver.xml” to return the “eduPersonPrincipalName” attribute but it only works for the last configured data connector listed in the “attribute-resolver.xml”
> file. I have moved the data connectors around and tested and it only works for the data connector listed at the bottom of the config.
>
> I know I’m missing something and if someone could help a newb out that would be great.
>
> Here is part of the attribute-resolver.xml file, and right now only users in AD3 can return the EPPN attribute:
>
>      <resolver:AttributeDefinition id="eduPersonPrincipalName" xsi:type="ad:Prescoped" sourceAttributeID="mail">
>
>          <resolver:Dependency ref="AD1" />
>
>          <resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:eduPersonPrincipalName" encodeType="false" />
>
>          <resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" friendlyName="eduPersonPrincipalName" encodeType="false" />
>
>      </resolver:AttributeDefinition>
>
>      <resolver:AttributeDefinition id="eduPersonPrincipalName" xsi:type="ad:Prescoped" sourceAttributeID="mail">
>
>          <resolver:Dependency ref="AD3" />
>
>          <resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:eduPersonPrincipalName" encodeType="false" />
>
>          <resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" friendlyName="eduPersonPrincipalName" encodeType="false" />
>
>      </resolver:AttributeDefinition>
>
>      <!-- ========================================== -->
>
>      <!--      Data Connectors                       -->
>
>      <!-- ========================================== -->
>
>      <resolver:DataConnector id="AD1" xsi:type="dc:LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc"
>
>          ldapURL="%{idp.attribute.resolver.LDAP.ldapURL1}"
>
>          baseDN="%{idp.attribute.resolver.LDAP.baseDN1}"
>
>          principal="%{idp.attribute.resolver.LDAP.bindDN1}"
>
>          principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential1}">
>
>          <dc:FilterTemplate>
>
>              <![CDATA[
>
>                  %{idp.attribute.resolver.LDAP.searchFilter1}
>
>              ]]>
>
>          </dc:FilterTemplate>
>
>      </resolver:DataConnector>
>
>      <resolver:DataConnector id="AD3" xsi:type="dc:LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc"
>
>          ldapURL="%{idp.attribute.resolver.LDAP.ldapURL3}"
>
>          baseDN="%{idp.attribute.resolver.LDAP.baseDN3}"
>
>          principal="%{idp.attribute.resolver.LDAP.bindDN3}"
>
>          principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential3}">
>
>          <dc:FilterTemplate>
>
>              <![CDATA[
>
>                  %{idp.attribute.resolver.LDAP.searchFilter3}
>
>              ]]>
>
>          </dc:FilterTemplate>
>
>      </resolver:DataConnector>
>
> Thanks,
>
> Joe
>
> This message is private and confidential. If you have received it in error, please notify the sender and remove it from your system.
>
>
>

-- 

  Douglas E. Engert  <DEEngert at gmail.com>



More information about the users mailing list