SP not receiving attributes from our IdP

Cantor, Scott cantor.2 at osu.edu
Thu Sep 15 22:58:33 EDT 2016


On 9/15/16, 10:38 PM, "users on behalf of Gould, Samuel" <users-bounces at shibboleth.net on behalf of Samuel.Gould at sdstate.edu> wrote:

> Yes, it means that we have to contact all our SPs, and yes, it means that we
>    had to work around some deficiencies in the install.sh script for Shib v3 (the
>    implicit assumption that entityID contains the hostname

It prompts you for whatever entityID you want to use, which can/should be the same one your old IdP used.

> -- thus generating bad certificates

There's nothing that matters in them except the key, which again should/must be the same key you used in the old IdP if you don't want to end up in a nightmarish transition for months or years. Or you have 10 SPs and all of this is really moot.

> Like I said in my response to David, I got my terminology wrong.  The SAML
> assertion _was_ bad.  I just meant to say that the authentication statement
> was OK.  Sorry about that.  Also, if the SP is requesting attributes (and they
> are), then it has to be SAML 2, right?

No. I don't know what you mean by requesting attributes, but SPs can't in general explicitly request them during SSO except by issuing back channel queries.

Without ruling out the SAML version, this is all blind guessing. The IdP will not push attributes with SAML 1 responses by default, so if this is a SAML 1 SP, that's why there's no attribute statement, regardless of what the IdP is told to do.

-- Scott
 



More information about the users mailing list