users Digest, Vol 55, Issue 115
Cantor, Scott
cantor.2 at osu.edu
Fri Jan 22 12:18:27 EST 2016
On 1/22/16, 12:09 PM, "users on behalf of Yasser Afifi" <users-bounces at shibboleth.net on behalf of yasser at 3dissue.com> wrote:
>I am trying to send attributes from idp to sp. I configured the soap back channel for this (any other suggestions?)
Yes, don't rely on that. The SAML 2 configuration includes the attributes in the original assertion by default and there's nothing else needed. You answered none of the questions I asked and are presumably using the wrong documentation to start with, making things even worse.
The Tomcat documentation for V3 is in [1].
You also need to read this [2]. All of it. You need to understand it. If you don't understand it, please ask a specific question about what you don't understand. It discussed what the back channel is used for and why it isn't needed in most cases.
The long and short of things is that you don't need the back channel and should stop using it and stop worrying about it. You are making your job harder, and ignoring every attempt made to tell you what the real problem is. The IdP is not successfully releasing any attributes yet. Once it does, your problem will go away. The IdP logs will indicate what the attribute steps are doing.
Peter already told you most of this I think.
-- Scott
[1] https://wiki.shibboleth.net/confluence/display/IDP30/ApacheTomcat8
[2] https://wiki.shibboleth.net/confluence/display/IDP30/SecurityAndNetworking
More information about the users
mailing list