Not getting an attribute statement in IDP assertion
Taylor Centers
taylor.centers at gmail.com
Tue Oct 27 10:38:42 EDT 2015
I'm trying to get my ldap database associated with the users in the
salesforce account, but no identifying information is being sent up with
the assertion. The Subject, NameID is a random transient value, and I
couldn't figure out how to make it a persistent hash of user data. I tried
changing saml-nameid.xml and saml-nameid.properties with no results, the
entire NameID block would disappear from the assertion if I tried changing
it.
Below is what I think the relevant files and fields for adding an attribute
to the assertion, in my case the user's email. But I am seeing no effect.
The logs look like it is getting the 'mail' attribute or at least parses
the configuration properly, but I the array for included attributes is
empty.
Does anyone notice something I'm doing wrong, or have an idea of how I can
get this working? Thanks for any input and advice.
*attribute-resolver.xml*
> <resolver:AttributeDefinition xsi:type="ad:Simple" id="mail">
<resolver:Dependency ref="myLDAP" />
> <resolver:AttributeEncoder xsi:type="enc:SAML1String"
> name="urn:mace:dir:attribute-def:mail" encodeType="false" />
> <resolver:AttributeEncoder xsi:type="enc:SAML2String"
> name="urn:oid:0.9.2342.19200300.100.1.3" friendlyName="mail"
> encodeType="false" />
> </resolver:AttributeDefinition>
>
> ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"
> baseDN="%{idp.attribute.resolver.LDAP.baseDN}"
> principal="%{idp.attribute.resolver.LDAP.bindDN}"
>
> principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}"
> useStartTLS="%{idp.attribute.resolver.LDAP.useStartTLS:true}">
> <dc:FilterTemplate>
> <![CDATA[
> %{idp.attribute.resolver.LDAP.searchFilter}
> ]]>
> </dc:FilterTemplate>
> <dc:StartTLSTrustCredential id="LDAPtoIdPCredential"
> xsi:type="sec:X509ResourceBacked">
>
> <sec:Certificate>%{idp.attribute.resolver.LDAP.trustCertificates}</sec:Certificate>
> </dc:StartTLSTrustCredential>
> </resolver:DataConnector>
<resolver:AttributeDefinition xsi:type="ad:Simple" id="mail">
>
<resolver:DataConnector id="myLDAP" xsi:type="dc:LDAPDirectory"
>
*attribute-filter.xml*
<afp:AttributeFilterPolicy id="example1">
> <afp:PolicyRequirementRule xsi:type=
> "basic:AttributeRequesterString" value="
> https://xxxxxxx.my.salesforce.com.org" />
> <afp:AttributeRule attributeID="mail">
> <afp:PermitValueRule xsi:type="basic:ANY" />
> </afp:AttributeRule>
> </afp:AttributeFilterPolicy>
*relying-party.xml*
<util:list id="shibboleth.RelyingPartyOverrides">
> <bean parent="RelyingPartyByName" c:relyingPartyIds="
> https://xxxxxxx.my.salesforce.com">
> <property name="profileConfigurations">
> <list>
> <bean parent="SAML2.SSO" p:encryptAssertions="false"
> p:postAuthenticationFlows="attribute-release"
> p:includeAttributeStatement="true" />
> </list>
> </property>
> </bean>
*idp-process.log*
2015-10-27 13:28:13,280 - INFO
> [net.shibboleth.utilities.java.support.service.AbstractReloadableService:172]
> - Service 'shibboleth.AttributeResolverService': Performing initial load
> 2015-10-27 13:28:13,280 - INFO
> [net.shibboleth.utilities.java.support.service.AbstractReloadableService:258]
> - Service 'shibboleth.AttributeResolverService': Reloading service
> configuration
> 2015-10-27 13:28:13,286 - INFO
> [net.shibboleth.ext.spring.util.SchemaTypeAwareXMLBeanDefinitionReader:317]
> - Loading XML bean definitions from file
> [~/shibboleth-idp/conf/attribute-resolver.xml]
> 2015-10-27 13:28:13,414 - INFO
> [net.shibboleth.idp.attribute.resolver.spring.BaseResolverPluginParser:58]
> - Parsing configuration for AttributeDefinition plugin with id : mail
> 2015-10-27 13:28:13,415 - INFO
> [net.shibboleth.idp.attribute.resolver.spring.ResolverPluginDependencyParser:52]
> - Parsing configuration for Dependency with pluginId : myLDAP
> 2015-10-27 13:28:13,438 - INFO
> [net.shibboleth.idp.attribute.resolver.spring.BaseResolverPluginParser:58]
> - Parsing configuration for DataConnector plugin with id : myLDAP
> 2015-10-27 13:28:13,488 - INFO
> [net.shibboleth.ext.spring.context.FilesystemGenericApplicationContext:510]
> - Refreshing ApplicationContext:shibboleth.AttributeResolverService:
> startup date [Tue Oct 27 13:28:13 UTC 2015]; parent: Root
> WebApplicationContext
> 2015-10-27 13:28:13,944 - INFO
> [net.shibboleth.ext.spring.service.ReloadableSpringService:378] - Service
> 'shibboleth.AttributeResolverService': Completed reload and swapped in
> latest configuration for service 'shibboleth.AttributeResolverService'
.....
> 2015-10-27 13:28:16,661 - INFO
> [net.shibboleth.idp.authn.impl.RemoteUserAuthServlet:135] -
> RemoteUserAuthServlet will process REMOTE_USER, along with attributes []
> and headers []
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151027/e49c76cc/attachment-0001.html>
More information about the users
mailing list