Two AD data connectors issue with Attribute-resolver
Douglas E Engert
deengert at gmail.com
Wed Oct 14 20:33:15 EDT 2015
If they are both in the same forest, you could just query the top domain, or use the Global Catalog.
On 10/14/2015 1:08 PM, Colon, Joseph wrote:
> Hello everyone,
>
> I am new to Shibboleth and have finally muddled through installation of IDPv3 on a Windows box and have the IDP configured as described here:
>
> /"Example for two Active Directory Directories with two DN Resolvers for each"/(https://wiki.shibboleth.net/confluence/display/IDP30/LDAPAuthnConfiguration#LDAPAuthnConfiguration-MultipleDirectories)
>
> So I have 2 AD domains both in the same forest and when I test against https://sp.testshib.org, I can see that the “ldap-authn-config.xml” is working as expected. Users from both domains can
> authenticate.
>
> Now I am trying to set up the “attribute-resolver.xml” to return the “eduPersonPrincipalName” attribute but it only works for the last configured data connector listed in the “attribute-resolver.xml”
> file. I have moved the data connectors around and tested and it only works for the data connector listed at the bottom of the config.
>
> I know I’m missing something and if someone could help a newb out that would be great.
>
> Here is part of the attribute-resolver.xml file, and right now only users in AD3 can return the EPPN attribute:
>
> <resolver:AttributeDefinition id="eduPersonPrincipalName" xsi:type="ad:Prescoped" sourceAttributeID="mail">
>
> <resolver:Dependency ref="AD1" />
>
> <resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:eduPersonPrincipalName" encodeType="false" />
>
> <resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" friendlyName="eduPersonPrincipalName" encodeType="false" />
>
> </resolver:AttributeDefinition>
>
> <resolver:AttributeDefinition id="eduPersonPrincipalName" xsi:type="ad:Prescoped" sourceAttributeID="mail">
>
> <resolver:Dependency ref="AD3" />
>
> <resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:eduPersonPrincipalName" encodeType="false" />
>
> <resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" friendlyName="eduPersonPrincipalName" encodeType="false" />
>
> </resolver:AttributeDefinition>
>
> <!-- ========================================== -->
>
> <!-- Data Connectors -->
>
> <!-- ========================================== -->
>
> <resolver:DataConnector id="AD1" xsi:type="dc:LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc"
>
> ldapURL="%{idp.attribute.resolver.LDAP.ldapURL1}"
>
> baseDN="%{idp.attribute.resolver.LDAP.baseDN1}"
>
> principal="%{idp.attribute.resolver.LDAP.bindDN1}"
>
> principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential1}">
>
> <dc:FilterTemplate>
>
> <![CDATA[
>
> %{idp.attribute.resolver.LDAP.searchFilter1}
>
> ]]>
>
> </dc:FilterTemplate>
>
> </resolver:DataConnector>
>
> <resolver:DataConnector id="AD3" xsi:type="dc:LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc"
>
> ldapURL="%{idp.attribute.resolver.LDAP.ldapURL3}"
>
> baseDN="%{idp.attribute.resolver.LDAP.baseDN3}"
>
> principal="%{idp.attribute.resolver.LDAP.bindDN3}"
>
> principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential3}">
>
> <dc:FilterTemplate>
>
> <![CDATA[
>
> %{idp.attribute.resolver.LDAP.searchFilter3}
>
> ]]>
>
> </dc:FilterTemplate>
>
> </resolver:DataConnector>
>
> Thanks,
>
> Joe
>
> This message is private and confidential. If you have received it in error, please notify the sender and remove it from your system.
>
>
>
--
Douglas E. Engert <DEEngert at gmail.com>
More information about the users
mailing list