SP not receiving attributes from our IdP
IAM David Bantz
dabantz at alaska.edu
Thu Sep 15 20:41:05 EDT 2016
On Thu, Sep 15, 2016 at 4:23 PM, Gould, Samuel <Samuel.Gould at sdstate.edu>
wrote:
> - According to the SAML Tracer FF plugin, no `<AttributeStatement>' is
> sent...
>
> - Verified that our IdP provides correct SAML assertions in response to
> this
>
> SP (determined with SAML Tracer FF plugin)
>
>
You may consider an authentication statement without attribute statement to
be "correct"
and it may be all that's needed by some SP's, but if your SP requires a
value of the attribute
eduPersonPrincipalName, you SAML assertion is at least incomplete!
Log file idp-process.log should have details of the interaction; increase
logging level to debug
if there isn't enough to identify why no attributes are being released.
Based on my experience, look first to match of your release policy to the
entityID of the SP
(if you're not releasing the same attribute bundle to every SP) - including
http/https and
presence or absence of trailing / in the names.
David Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160915/c632393a/attachment.html>
More information about the users
mailing list