Box.com and Shibboleth
Chad Sutton
casutton at noctrl.edu
Thu Mar 3 13:34:48 EST 2016
So it turns out, that this little bugger from ldap.properties was the
main problem the whole time.
idp.attribute.resolver.LDAP.returnAttributes =
cn,homephone,mail,uid,sn,givenName
By default it only had cn,homephone,mail. Once I added uid,sn,givenName,
those properties were no longer null and they started passing. I feel
like banging my head against my desk over and over. :)
Regards,
Chad Sutton - North Central College ITS
casutton at noctrl.edu
630-637-5448
On 03/03/2016 09:04 AM, Chad Sutton wrote:
> Another update. It seems that while mail is being passed, sn
> (urn:oid:2.5.4.4) and givenName (urn:oid:2.5.4.42) aren't being passed.
>
> While I've gotten two different answers from them on what they call
> "subject" (an earlier one that said they were using the ePPN
> "urn:oid:1.3.6.1.4.1.5923.1.1.1.6" which was obviously wrong), this is
> the latest info they have sent me.
>
> first_name urn:oid:2.5.4.42 (Assertion)
> subject urn:oid:1.3.6.1.4.1.5923.1.1.1.6 (Assertion)
> last_name urn:oid:2.5.4.4 (Assertion)
>
> As I'm still pretty new to all of this, it seems to me that as I have
> never referenced "subject" in my config as
> urn:oid:1.3.6.1.4.1.5923.1.1.1.6 that because I've assigned that to
> the mail attributeID that it doesn't matter what the "friendly name"
> of the attributeID is and that only the urn code is what is being
> used. As I'm using the correct codes for "sn" and "givenName"
> shouldn't they be passing too?
>
> I feel like the crossed wires are on their end and not mine, but being
> so new to this I'm not super confident about that yet.
>
> Are these the same AttributeDefinitions others are using for Box?
>
>
> Regards,
> Chad Sutton - North Central College ITS
> casutton at noctrl.edu
> 630-637-5448
>
> On 02/29/2016 09:25 AM, Chad Sutton wrote:
>> I'm at my wit's end here. We have an existing Shib IDP that is
>> working with a number of other SP's. But we couldn't seem to get it
>> working properly with Box.com. I followed the wiki
>> https://spaces.internet2.edu/display/NetPlusIDG/BoxIDG.
>>
>> I'm fairly new to Shibboleth so bare with me. Everything looks like
>> it is working except when it comes to passing Box the
>> eduPersonPrincipalName, which is really all that Box requires. It
>> doesn't pass anything to them. I noticed that the
>> PasswordProtectedTransport in my logs never contains any field names
>> like it does for other SPs.
>>
>> I've have since created a test server so I can mess with XML files
>> and restart Tomcat as much as I want. I am getting the same thing on
>> the test box.
>>
>>
>> A snip from my idp-process.log
>>
>> 2016-02-29 08:38:38,745 - INFO
>> [net.shibboleth.idp.authn.impl.RemoteUserAuthServlet:193] -
>> RemoteUserAuthServlet will process REMOTE_USER, along with attributes
>> [] and headers []
>> 2016-02-29 08:39:59,781 - INFO [org.ldaptive.auth.Authenticator:259]
>> - Authentication succeeded for dn: cn=casutton,ou=Admstr,ou=Napvil,o=NCC
>> 2016-02-29 08:39:59,794 - INFO
>> [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:139]
>> - Profile Action ValidateUsernamePasswordAgainstLDAP: Login by
>> 'casutton' succeeded
>> 2016-02-29 08:40:00,327 - ERROR
>> [net.shibboleth.idp.profile.impl.ResolveAttributes:240] - Profile
>> Action ResolveAttributes: Error resolving attributes: Invalid
>> Attribute resolver configuration
>> 2016-02-29 08:40:00,989 - WARN
>> [net.shibboleth.idp.consent.flow.ar.impl.AbstractAttributeReleaseAction:155]
>> - Profile Action PopulateAttributeReleaseContext: Unable to locate
>> attribute context
>> 2016-02-29 08:40:02,513 - INFO [Shibboleth-Audit.SSO:241] -
>> 20160229T144002Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|aTaVxkNsrMagR4Tsw3dkh5l-TGR|box.net|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://logintest.noctrl.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_f3849b289760d44449f9bfe62d6f459e|casutton|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||AAdzZWNyZXQxxxKquNVPpR5LnofTIk0ea6li7WEdmUEbq73t1trVyy0qmhwrpQqqRs93c3KvN2CKOCYhfPgpkI+m6tk9A3s0lgwRsyjjyWfzgPj5TKvI|_12beaf680eaf737d7b4d9ef639e27a4f|
>>
>> I'm assuming that this is a problem with my attribute-filter.xml
>> file? Here is what I have added for Box, which is direct from the
>> wiki page.
>>
>> <AttributeFilterPolicy id="BoxSSO">
>> <PolicyRequirementRule xsi:type="basic:AttributeRequesterString"
>> value="https://services.box.com/sp"/>
>> <AttributeRule attributeID="eduPersonPrincipalName">
>> <PermitValueRule xsi:type="basic:ANY"/>
>> </AttributeRule>
>> <AttributeRule attributeID="sn">
>> <PermitValueRule xsi:type="basic:ANY"/>
>> </AttributeRule>
>> <AttributeRule attributeID="givenName">
>> <PermitValueRule xsi:type="basic:ANY"/>
>> </AttributeRule>
>> </AttributeFilterPolicy>
>>
>> Any ideas of where I need to focus to get this working? The Box folks
>> aren't much help. They expect everyone to figure this out for
>> themselves, which is fair I guess, but I imagine there are tons of
>> EDUs that use Shibboleth and Box. So I know this works. :)
>>
>
>
More information about the users
mailing list