Attributes not being release from AD

Michael Richter mrichter at coastal.edu
Thu Feb 11 15:32:40 EST 2016


Hello all,
    I'm a bit new Shibboleth and have gotten most of the way set up.  I am able to authenticate successfully, but I'm having issues releasing attributes from AD via LDAP using the attribute-resolver.xml and attribute-filter.xml.  I've created the Data connector in the Attribute-resolver.xml:


<resolver:DataConnector id="coastal" xsi:type="dc:LDAPDirectory"
    ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"
    baseDN="%{idp.attribute.resolver.LDAP.baseDN}"
    principal="%{idp.attribute.resolver.LDAP.bindDN}"
    principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}"
    useStartTLS="%{idp.attribute.resolver.LDAP.useStartTLS:true}">
    <dc:FilterTemplate>
        <![CDATA[
            %{idp.attribute.resolver.LDAP.searchFilter}
        ]]>
    </dc:FilterTemplate>
    <dc:ReturnAttributes>%{idp.attribute.resolver.LDAP.returnAttributes}</dc:ReturnAttributes>
    <dc:StartTLSTrustCredential id="LDAPtoIdPCredential" xsi:type="sec:X509ResourceBacked">
        <sec:Certificate>%{idp.attribute.resolver.LDAP.trustCertificates}</sec:Certificate>
    </dc:StartTLSTrustCredential>
    </resolver:DataConnector>

Here's my ldap.properties file:

# LDAP authentication configuration, see authn/ldap-authn-config.xml

## Authenticator strategy, either anonSearchAuthenticator, bindSearchAuthenticator, directAuthenticator, adAuthenticator
idp.authn.LDAP.authenticator= bindSearchAuthenticator

## Connection properties ##
#idp.authn.LDAP.ldapURL= xxxx:389
idp.authn.LDAP.ldapURL= xxxx:389
#idp.authn.LDAP.useStartTLS                     = false
idp.authn.LDAP.useSSL                          = false
#idp.authn.LDAP.connectTimeout                  = 3000

## SSL configuration, either jvmTrust, certificateTrust, or keyStoreTrust
#idp.authn.LDAP.sslConfig                       = certificateTrust
## If using certificateTrust above, set to the trusted certificate's path
idp.authn.LDAP.trustCertificates= %{idp.home}/credentials/ldap-server.crt
## If using keyStoreTrust above, set to the truststore path
idp.authn.LDAP.trustStore= %{idp.home}/credentials/ldap-server.truststore

## Return attributes during authentication
## NOTE: this is not used during attribute resolution; configure that directly in the
## attribute-resolver.xml configuration via a DataConnector's <dc:ReturnAttributes> element
idp.authn.LDAP.returnAttributes= cn,mail

## DN resolution properties ##

# Search DN resolution, used by anonSearchAuthenticator, bindSearchAuthenticator
# for AD: CN=Users,DC=example,DC=org
idp.authn.LDAP.baseDN= DC=coastal, DC=edu
idp.authn.LDAP.subtreeSearch                   = true
idp.authn.LDAP.userFilter= (sAMAccountName={user})
# bind search configuration
# for AD: idp.authn.LDAP.bindDN=adminuser at domain.com<mailto:idp.authn.LDAP.bindDN=adminuser at domain.com>
idp.authn.LDAP.bindDN= xxxx at coastal.edu<mailto:xxxx at coastal.edu>
#idp.authn.LDAP.bindDNCredential= xxxx
idp.authn.LDAP.bindDNCredential= xxxx

# Format DN resolution, used by directAuthenticator, adAuthenticator
# for AD use idp.authn.LDAP.dnFormat=%s at domain.com<mailto:idp.authn.LDAP.dnFormat=%25s at domain.com>
idp.authn.LDAP.dnFormat= %s at coastal.edu<mailto:%25s at coastal.edu>

# LDAP attribute configuration, see attribute-resolver.xml
idp.attribute.resolver.LDAP.ldapURL= %{idp.authn.LDAP.ldapURL}
idp.attribute.resolver.LDAP.baseDN= %{idp.authn.LDAP.baseDN}
idp.attribute.resolver.LDAP.bindDN= %{idp.authn.LDAP.bindDN}
idp.attribute.resolver.LDAP.bindDNCredential= %{idp.authn.LDAP.bindDNCredential}
idp.attribute.resolver.LDAP.useStartTLS= %{idp.authn.LDAP.useStartTLS:true}
idp.attribute.resolver.LDAP.trustCertificates= %{idp.authn.LDAP.trustCertificates}
idp.attribute.resolver.LDAP.searchFilter= (uid=$requestContext.principalName)
idp.attribute.resolver.LDAP.returnAttributes = sn,displayName,mail,sAMAccountName

I've then defined some attributes to be released:

<resolver:AttributeDefinition xsi:type="ad:Prescoped" id="eduPersonPrincipalName" sourceAttributeID="cn">
        <resolver:Dependency ref="coastal" />
        <resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:eduPersonPrincipalName" encodeType="false" />
        <resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" friendlyName="eduPersonPrincipalName" encodeType="false" />
    </resolver:AttributeDefinition>

                <resolver:AttributeDefinition xsi:type="ad:Simple" id="sn" sourceAttributeID="sn">
        <resolver:Dependency ref="coastal" />
        <resolver:AttributeEncoder xsi:type="enc:SAML1String" name="urn:mace:dir:attribute-def:sn" encodeType="false" />
        <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="urn:oid:2.5.4.4" friendlyName="sn" encodeType="false" />
    </resolver:AttributeDefinition>

    <resolver:AttributeDefinition id="mail" xsi:type="ad:Simple" sourceAttributeID="mail">
        <resolver:Dependency ref="coastal" />
        <resolver:AttributeEncoder xsi:type="enc:SAML1String" name="urn:mace:dir:attribute-def:mail" encodeType="false" />
        <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="urn:oid:0.9.2342.19200300.100.1.3" friendlyName="mail" encodeType="false" />
    </resolver:AttributeDefinition>

In my Attribute-filter.xml I've added the entries (I'm testing using the incommon test bed)

<afp:AttributeFilterPolicy id="Incommon Federation">
        <afp:PolicyRequirementRule xsi:type="basic:AttributeRequesterString" value="https://fm.incommon.org/sp" />

      <afp:AttributeRule attributeID="eduPersonPrincipalName">
            <afp:PermitValueRule xsi:type="basic:ANY" />
        </afp:AttributeRule>


                                <afp:AttributeRule attributeID="mail">
            <afp:PermitValueRule xsi:type="basic:ANY" />
        </afp:AttributeRule>



                                <afp:AttributeRule attributeID="displayName">
            <afp:PermitValueRule xsi:type="basic:ANY" />
        </afp:AttributeRule>


    </afp:AttributeFilterPolicy>




When I log in via the test bed I'm successfully authenticated, but receive no attributes:


2016-02-11 14:51:07,594 - INFO [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:179] - Profile Action ValidateUsernamePasswordAgainstLDAP: Login by 'mrichter' succeeded
2016-02-11 14:51:12,062 - INFO [net.shibboleth.idp.attribute.resolver.AbstractResolverPlugin:191] - Resolver plugin 'coastal' produced no value.
2016-02-11 14:51:12,500 - INFO [Shibboleth-Audit.SSO:241] - 20160211T195112Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_3dc45b2cdb437a697a2bc4e21085e075|https://fm.incommon.org/sp|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://shib1.coastal.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_fb8de51164a0df1a8eb8e3f1d14a2bdf|mrichter|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||AAdzZWNyZXQxNUWzXq1oYkuk0JwultB0V44+SfEvgjVWhjLysjTMt2F4umkFW8bp2EJ1VEjvIXBdEZ5PEDKkgX2Oosabw9Eu69rNhekwhjic0gMpUpFXhaULSxoGL9OHs2mPhZQyjUBzLw==|_0ad49c4a3bf03d91688ee662da41acd9
2016-02-11 14:55:35,082 - INFO [net.shibboleth.idp.attribute.resolver.AbstractResolverPlugin:191] - Resolver plugin 'coastal' produced no value.



Any  ideas what I'm missing.  Again, I'm fairly new to Shibboleth, so sorry if I missed something obvious.  I tried to research this pretty extensively before posting.  Thanks!

Mike

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160211/d1ba0bb5/attachment-0001.html>


More information about the users mailing list