Aw: Re: Re: shibboleth - uncaught runtime exception on request

Ilya Rumyantsev iliggio at gmx.de
Wed Dec 7 10:53:27 EST 2016


I am sorry, I don't understand: 

" hat's fine. Except with a query. You cannot do that, short of using a DN formatted NameID so that the query that comes back in carries the DN. "

The third-party SP speaks SAML 1, how would I avoid it for this request?

by the second request I mean 
the request where subjects are not defined (the back channel requests )

What would I need to change, could you please point to the documentation?

Thanks a lot 


> Gesendet: Mittwoch, 07. Dezember 2016 um 16:30 Uhr
> Von: "Cantor, Scott" <cantor.2 at osu.edu>
> An: "Shib Users" <users at shibboleth.net>
> Betreff: Re: Aw: Re: shibboleth - uncaught runtime exception on request
>
> On 12/7/16, 10:24 AM, "users on behalf of Ilya Rumyantsev" <users-bounces at shibboleth.net on behalf of iliggio at gmx.de> wrote:
> 
> >    The problem now is: I need the certificate subject due to an Ldap Attribute DataConnector and of course on the second
> > request there is no $dnFromCert variable available
> 
> What second request?
> 
> > What I am trying to achieve is:
> 
> That's fine. Except with a query. You cannot do that, short of using a DN formatted NameID so that the query that comes back in carries the DN.
> 
> All you get on queries is the NameID and then the mapping from that back to a canonical principal name bound to that NameID. That's it.
> 
> There is no reason you should be using SAML 1 here. So don't.
> 
> -- Scott
> 
> 
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> 


More information about the users mailing list