SP not receiving attributes from our IdP
Gould, Samuel
Samuel.Gould at sdstate.edu
Thu Sep 15 20:23:51 EDT 2016
Greetings!
I am experiencing a Shibboleth IdP configuration problem (mentioned in the
subject line) and would be grateful if someone on this mailing list could lend
some advice. I still consider myself a beginner in Shibboleth administration,
so perhaps the root cause of this problem will be easy for you to diagnose.
General background:
- My organization is simultaneously running a Shib v2 and Shib v3 IdP
- We just recently spun up the Shib v3 IdP, and gave it a different hostname
than the Shib v2 IdP; the entity IDs are the same
- Our plan is to gradually transition SPs from using the v2 IdP to the v3 IdP
- I do not have access to the v2 IdP, but I am still responsible for updating
configuration files and directing its administration; a colleague of mine
performs my requested actions
- The v2 IdP is running on Tomcat; I think it is using Catalina as the web
server, but it might be using IIS
- I have access to the v3 IdP, which is running on Tomcat/Catalina/RHEL 7; I
was the one who deployed the stack
Problem-specific background:
- Within a short time frame, we need to establish SSO with a specific SP
- Both our organization and this SP are members of the InCommon federation
- Currently, InCommon has our v2 endpoints listed
- We do not have time to push our new v3 endpoints to InCommon before this SP
must be working
- Even if we gave the SP standalone metadata for our v3 IdP (instead of going
through InCommon), our v3 IdP is not well tested enough for management to
feel comfortable enough to use it within our short timeframe
- Due to the above, we are configuring our v2 IdP to work with this SP
The problem:
- The SP is not receiving any attributes from our IdP
- According to the SAML Tracer FF plugin, no `<AttributeStatement>' is sent
- Technical personnel at the SP report that they are logging something like
"not receiving eduPersonPrincipalName"
What we have done:
- Updated `attribute-filter.xml' to release attributes requested by the SP
- Verified that the requested attributes exist in `attribute-resolver.xml'
- Restarted Tomcat
- Verified that our IdP provides correct SAML assertions in response to this
SP (determined with SAML Tracer FF plugin)
Is there anything else I can do or any more information I can provide to aid
diagnostics? Or does someone already know what's going on? :)
Thanks,
Sam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160916/9c1bdeba/attachment-0001.html>
More information about the users
mailing list