Aw: Re: Re: shibboleth - uncaught runtime exception on request
Ilya Rumyantsev
iliggio at gmx.de
Wed Dec 7 10:53:27 EST 2016
I am sorry, I don't understand:
" hat's fine. Except with a query. You cannot do that, short of using a DN formatted NameID so that the query that comes back in carries the DN. "
The third-party SP speaks SAML 1, how would I avoid it for this request?
by the second request I mean
the request where subjects are not defined (the back channel requests )
What would I need to change, could you please point to the documentation?
Thanks a lot
> Gesendet: Mittwoch, 07. Dezember 2016 um 16:30 Uhr
> Von: "Cantor, Scott" <cantor.2 at osu.edu>
> An: "Shib Users" <users at shibboleth.net>
> Betreff: Re: Aw: Re: shibboleth - uncaught runtime exception on request
>
> On 12/7/16, 10:24 AM, "users on behalf of Ilya Rumyantsev" <users-bounces at shibboleth.net on behalf of iliggio at gmx.de> wrote:
>
> > The problem now is: I need the certificate subject due to an Ldap Attribute DataConnector and of course on the second
> > request there is no $dnFromCert variable available
>
> What second request?
>
> > What I am trying to achieve is:
>
> That's fine. Except with a query. You cannot do that, short of using a DN formatted NameID so that the query that comes back in carries the DN.
>
> All you get on queries is the NameID and then the mapping from that back to a canonical principal name bound to that NameID. That's it.
>
> There is no reason you should be using SAML 1 here. So don't.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
More information about the users
mailing list