Box.com and Shibboleth

Chad Sutton casutton at noctrl.edu
Wed Mar 2 12:20:14 EST 2016


Solved.

It is working! So for a lark I added the mail attribute 
(oid:0.9.2342.19200300.100.1.3) to the attribute-filter.xml file in 
addition to eduPersonPrincipalName (oid:0.9.2342.19200300.100.1.3) which 
was the recommended field on the wiki page and by Box. Turns out that 
they really just wanted mail. Is this what other people have used? 
Perhaps I need to update 
https://spaces.internet2.edu/display/NetPlusIDG/BoxIDG#BoxIDG-ExampleConfigurationforSAMLImplementations 
with this information?

Regards,
Chad Sutton - North Central College ITS
casutton at noctrl.edu
630-637-5448

On 02/29/2016 09:25 AM, Chad Sutton wrote:
> I'm at my wit's end here. We have an existing Shib IDP that is working 
> with a number of other SP's. But we couldn't seem to get it working 
> properly with Box.com. I followed the wiki 
> https://spaces.internet2.edu/display/NetPlusIDG/BoxIDG.
>
> I'm fairly new to Shibboleth so bare with me. Everything looks like it 
> is working except when it comes to passing Box the 
> eduPersonPrincipalName, which is really all that Box requires. It 
> doesn't pass anything to them.  I noticed that the 
> PasswordProtectedTransport in my logs never contains any field names 
> like it does for other SPs.
>
> I've have since created a test server so I can mess with XML files and 
> restart Tomcat as much as I want. I am getting the same thing on the 
> test box.
>
>
> A snip from my idp-process.log
>
> 2016-02-29 08:38:38,745 - INFO 
> [net.shibboleth.idp.authn.impl.RemoteUserAuthServlet:193] - 
> RemoteUserAuthServlet will process REMOTE_USER, along with attributes 
> [] and headers []
> 2016-02-29 08:39:59,781 - INFO [org.ldaptive.auth.Authenticator:259] - 
> Authentication succeeded for dn: cn=casutton,ou=Admstr,ou=Napvil,o=NCC
> 2016-02-29 08:39:59,794 - INFO 
> [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:139] - 
> Profile Action ValidateUsernamePasswordAgainstLDAP: Login by 
> 'casutton' succeeded
> 2016-02-29 08:40:00,327 - ERROR 
> [net.shibboleth.idp.profile.impl.ResolveAttributes:240] - Profile 
> Action ResolveAttributes: Error resolving attributes: Invalid 
> Attribute resolver configuration
> 2016-02-29 08:40:00,989 - WARN 
> [net.shibboleth.idp.consent.flow.ar.impl.AbstractAttributeReleaseAction:155] 
> - Profile Action PopulateAttributeReleaseContext: Unable to locate 
> attribute context
> 2016-02-29 08:40:02,513 - INFO [Shibboleth-Audit.SSO:241] - 
> 20160229T144002Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|aTaVxkNsrMagR4Tsw3dkh5l-TGR|box.net|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://logintest.noctrl.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_f3849b289760d44449f9bfe62d6f459e|casutton|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||AAdzZWNyZXQxxxKquNVPpR5LnofTIk0ea6li7WEdmUEbq73t1trVyy0qmhwrpQqqRs93c3KvN2CKOCYhfPgpkI+m6tk9A3s0lgwRsyjjyWfzgPj5TKvI|_12beaf680eaf737d7b4d9ef639e27a4f|
>
> I'm assuming that this is a problem with my attribute-filter.xml file? 
> Here is what I have added for Box, which is direct from the wiki page.
>
>   <AttributeFilterPolicy id="BoxSSO">
>     <PolicyRequirementRule xsi:type="basic:AttributeRequesterString" 
> value="https://services.box.com/sp"/>
>     <AttributeRule attributeID="eduPersonPrincipalName">
>       <PermitValueRule xsi:type="basic:ANY"/>
>     </AttributeRule>
>     <AttributeRule attributeID="sn">
>       <PermitValueRule xsi:type="basic:ANY"/>
>     </AttributeRule>
>     <AttributeRule attributeID="givenName">
>       <PermitValueRule xsi:type="basic:ANY"/>
>     </AttributeRule>
>   </AttributeFilterPolicy>
>
> Any ideas of where I need to focus to get this working? The Box folks 
> aren't much help. They expect everyone to figure this out for 
> themselves, which is fair I guess, but I imagine there are tons of 
> EDUs that use Shibboleth and Box. So I know this works. :)
>




More information about the users mailing list