login failed for scitation.aip.org in IDP3
Peter Schober
peter.schober at univie.ac.at
Mon Mar 14 10:03:00 EDT 2016
* Hong Ye <hy93 at cornell.edu> [2016-03-13 15:48]:
> We upgraded to IDP 3 this morning and found authentication from
> scitation.aip.org<http://scitation.aip.org> stopped working.This
> site uses SAML1 and back channel query.
I hadn't dealt with that SP myself yet and none of the 5 academic
federations that have registered this SP bothered to include
RequestedAttribute elements:
https://met.refeds.org/met/entity/https%253A%252F%252Fscitation.aip.org%252Fshibboleth/
But you should be able to find out what attribute that SP requested
(and consequently what attributes your IDP released to that SP) by
looking at your IDPv2 audit log files.
If that's mostly non-PII data (I'd expect to find an entitlement --
likely with the common-lib-terms value as the only attribute released)
you should probably just push that attribute over the browser also for
SAML1 (includeAttributeStatement was the setting in v2, check the docs
for v3), and forget about the back channel.
OTOH you may be having other SPs that stopped working with a
misconfigured back channel, you might just not have discovered them?
Then fixing the back channel would be in order, of course.
-peter
More information about the users
mailing list