IdP v3 not releasing attributes to SAML1 SPs

Mark K. Miller max at psu.edu
Mon Aug 22 12:22:48 EDT 2016


On Mon, 22 Aug 2016, Cantor, Scott wrote:

>> I've had a few more reports today of SPs not working.  The first thing
>> I've noticed in the idp-process.log is that these SP are all still using
>> SAML1.  It appears that the authentication happens without issue, but I'm
>> not seeing any attributes get sent to these SAML1 SPs.
>
> I would imagine you broke the back-channel in some way and queries 
> aren't working.

I certainly didn't intend to change anything at all about the back-channel.

>> Is this something that's know to break in the v2-to-v3 upgrade?
>
> It's entirely identical

Not after our IdP was upgraded, it's not.  :-(

>                         save for how transient IDs are generated and 
> reversed by default.
>
> -- Scott

On a more positive note, at least two thirds of the vendors have seemed 
very cooperative about changing their SP from SAML1 to SAML2 (so far.)

Thanks,

Max


More information about the users mailing list