SAML1.1 attribute release on Shib 3

Morris, Andi amorris at cardiffmet.ac.uk
Wed Feb 15 12:32:07 EST 2017


Thanks everyone! Rod nailed it with the attribute push. Adding the following line to my default relyingparty.xml file has released the attributes over SAML1.1.

<bean parent="Shibboleth.SSO" p:includeAttributeStatement = "true" />

I'll look to implement this in production only for known SAML1.1 service providers.

Thanks again.

Cheers,
Andi


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 15 February 2017 17:08
To: Shib Users <users at shibboleth.net>
Subject: Re: SAML1.1 attribute release on Shib 3

On 2/15/17, 12:05 PM, "users on behalf of Steve Glover" <users-bounces at shibboleth.net on behalf of Steve.Glover at jisc.ac.uk> wrote:

> Maybe it's your configuration after all....

> $ openssl s_client -connect idp3.dev.cardiffmet.ac.uk:8443 -showcerts
> CONNECTED(00000003)
> 139985115449248:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:184:

Unless you're using a very current OpenSSL and even then likely forcing TLS 1.0 at least, that's about what I'd expect from a properly configured TLS endpoint. Seeing that sort of failure is more about the client than the server.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________

[Cardiff Metropolitan University - Queens Anniversary Prizes 2015]<http://www.cardiffmet.ac.uk/news/Pages/Cardiff-Met-research-recognised-in-Queens-Anniversary-Prizes-for-Higher-and-Further-Education.aspx>


More information about the users mailing list