SP not receiving attributes from our IdP

Gould, Samuel Samuel.Gould at sdstate.edu
Thu Sep 15 20:23:51 EDT 2016


Greetings!

I am experiencing a Shibboleth IdP configuration problem (mentioned in the
subject line) and would be grateful if someone on this mailing list could lend
some advice.  I still consider myself a beginner in Shibboleth administration,
so perhaps the root cause of this problem will be easy for you to diagnose.

General background:

  - My organization is simultaneously running a Shib v2 and Shib v3 IdP
  - We just recently spun up the Shib v3 IdP, and gave it a different hostname
    than the Shib v2 IdP; the entity IDs are the same
  - Our plan is to gradually transition SPs from using the v2 IdP to the v3 IdP
  - I do not have access to the v2 IdP, but I am still responsible for updating
    configuration files and directing its administration; a colleague of mine
    performs my requested actions
  - The v2 IdP is running on Tomcat; I think it is using Catalina as the web
    server, but it might be using IIS
  - I have access to the v3 IdP, which is running on Tomcat/Catalina/RHEL 7; I
    was the one who deployed the stack

Problem-specific background:

  - Within a short time frame, we need to establish SSO with a specific SP
  - Both our organization and this SP are members of the InCommon federation
  - Currently, InCommon has our v2 endpoints listed
  - We do not have time to push our new v3 endpoints to InCommon before this SP
    must be working
  - Even if we gave the SP standalone metadata for our v3 IdP (instead of going
    through InCommon), our v3 IdP is not well tested enough for management to
    feel comfortable enough to use it within our short timeframe
  - Due to the above, we are configuring our v2 IdP to work with this SP

The problem:

  - The SP is not receiving any attributes from our IdP
  - According to the SAML Tracer FF plugin, no `<AttributeStatement>' is sent
  - Technical personnel at the SP report that they are logging something like
    "not receiving eduPersonPrincipalName"

What we have done:

  - Updated `attribute-filter.xml' to release attributes requested by the SP
  - Verified that the requested attributes exist in `attribute-resolver.xml'
  - Restarted Tomcat
  - Verified that our IdP provides correct SAML assertions in response to this
    SP (determined with SAML Tracer FF plugin)

Is there anything else I can do or any more information I can provide to aid
diagnostics?  Or does someone already know what's going on? :)

Thanks,
Sam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160916/9c1bdeba/attachment-0001.html>


More information about the users mailing list