Unencrypted NameID

Robert Lamothe robert_lamothe at yahoo.com
Fri Feb 12 09:16:43 EST 2016


Here are the logs from shibtest.org, I'm using that for debugging as the log files are easier to read than from the SP.

2016-02-12 08:55:27 DEBUG Shibboleth.SSO.SAML2 [5]: decrypted Assertion: <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_4dd7fe1bbf06b74768126d64839634a3" IssueInstant="2016-02-12T13:55:26.742Z" Version="2.0"><saml2:Issuer>https://shibboleth.umassmed.edu/idp/shibboleth</saml2:Issuer><saml2:Subject><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="https://shibboleth.umassmed.edu/idp/shibboleth" SPNameQualifier="https://sp.testshib.org/shibboleth-sp">AAhzZWNyZXQzMpcOxEiCUYgvWjbRtBc9wjXVN27uQFSNDhJR9/Ou+kVuEcTKWZtZlQcQpB26GcK3BuP4tqV+G97nr8BB1GODPNx1DVeGUSjtlz7zUWvr5lHanlhhIqp3z1USlRO0bJgsGE1A7sDcluzHLks=</saml2:NameID><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData Address="172.17.44.170" InResponseTo="_049b45a5edfe7180db724996b18f1b0a" NotOnOrAfter="2016-02-12T14:00:26.753Z" Recipient="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions NotBefore="2016-02-12T13:55:26.742Z" NotOnOrAfter="2016-02-12T14:00:26.742Z"><saml2:AudienceRestriction><saml2:Audience>https://sp.testshib.org/shibboleth-sp</saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement AuthnInstant="2016-02-12T13:55:26.509Z" SessionIndex="_54b0be6b4dfafd0e8bb03a67753c71a4"><saml2:SubjectLocality Address="172.17.44.170"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement><saml2:AttributeStatement><saml2:Attribute FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>LamotheR</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Robert.Lamothe at umassmed.edu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>staff</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://shibboleth.umassmed.edu/idp/shibboleth" SPNameQualifier="https://sp.testshib.org/shibboleth-sp">XgQzYSIOcCKtS8gcaeSXYCyfsfE=</saml2:NameID></saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Lamothe, Robert</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Lamothe</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Robert</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>lamother at umassmed.edu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="title" Name="urn:oid:2.5.4.12" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Sr System Admin.</saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion>


    According to  CustomNameIDGenerationConfiguration, I followed the steps in General Procedure and uncommented out the code for the SAML 2.0 Email Format Examples, I included that in my last message.
   I'm a little confused though, the example has a type of rn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress The metadata is asking for urn:oasis:names:tc:SAML:2.0:nameid-format:transient Do they need to match?  The metadata was generated by the SP so I'm thinking the format has to remain as they sent it, is that true?  Can I change  <NameIDFormat> to match what's in saml-nameid.xml?  Or do I change saml-nameid.xml to match the <NameIDFormat> that our SP is looking for?
    Please correct me if I'm wrong, but I need to make changes in saml-nameid.xml, and possibly saml-nameid.properties right?  I'm digesting every document I can find, but few provide practical examples, they're all running at a high level.  

    If I understand the example in CustomNameIDGenerationConfiguration, my failure is most likely in step 4 or 5, either my format is wrong or it's my trigger.
Regards-Bob
--
Bob Lamothe
robert_lamothe at yahoo.com
KB1BOB
603-918-6336

 

    On Thursday, February 11, 2016 7:39 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
 

 > I added the following to my attribute-filter.xml:

The default behavior of the attribute-sourced NameID generator is to rely on released attributes, so the attribute you need to "release" to the SP is the mail attribute. So what you're doing here isn't going to help. Whether that's your problem is a different issue, but it won't work until you fix that. Releasing "NameID" is meaningless. There is no such attribute.

You can also, if you prefer, configure the generator plugin to allow sourcing of "unfiltered" attributes so that you don't have to explicitly release the source attribute by setting the useUnfilteredAttributes property of the generator.

>    I suspect that the transientid is unecessary but a colleague suggested it
> based on what we got from our SP in the metadata which is below:

There is nothing in the filter policy that has any effect on transient identifiers, period.

>    I think I have everything in place but I'm still getting a transient string rather
> than the email address.  What am I missing?

Well, with no logs, I'm just guessing. You didn't release mail, so that isn't going to work, but even if you did, I don't think there's anything here that would suggest it will pick anything but transient, because the metadata is explicit about wanting that.

I've documented the NameID Format selection algorithm in as much detail as I know how to:

https://wiki.shibboleth.net/confluence/display/IDP30/NameIDGenerationConfiguration

I think it should be quite clear from that that if the metadata requests transient, that's what you're getting.

We can have a discussion about whether that's the right thing to do, but that's what we do. If the metadata lists only transient, I don't believe there's *anything* you could do that would give you a different outcome. The most it would do is include nothing, if you blocked the support for transients. It would never include a Format that the SP doesn't support. If the metadata contains *nothing*, then the rest of the machinery takes over because that means there is no preference being expressed.

That metadata is simply wrong.

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160212/6248ff8d/attachment-0001.html>


More information about the users mailing list