SAML1.1 attribute release on Shib 3
Morris, Andi
amorris at cardiffmet.ac.uk
Wed Feb 15 12:32:07 EST 2017
Thanks everyone! Rod nailed it with the attribute push. Adding the following line to my default relyingparty.xml file has released the attributes over SAML1.1.
<bean parent="Shibboleth.SSO" p:includeAttributeStatement = "true" />
I'll look to implement this in production only for known SAML1.1 service providers.
Thanks again.
Cheers,
Andi
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 15 February 2017 17:08
To: Shib Users <users at shibboleth.net>
Subject: Re: SAML1.1 attribute release on Shib 3
On 2/15/17, 12:05 PM, "users on behalf of Steve Glover" <users-bounces at shibboleth.net on behalf of Steve.Glover at jisc.ac.uk> wrote:
> Maybe it's your configuration after all....
> $ openssl s_client -connect idp3.dev.cardiffmet.ac.uk:8443 -showcerts
> CONNECTED(00000003)
> 139985115449248:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:184:
Unless you're using a very current OpenSSL and even then likely forcing TLS 1.0 at least, that's about what I'd expect from a properly configured TLS endpoint. Seeing that sort of failure is more about the client than the server.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________
[Cardiff Metropolitan University - Queens Anniversary Prizes 2015]<http://www.cardiffmet.ac.uk/news/Pages/Cardiff-Met-research-recognised-in-Queens-Anniversary-Prizes-for-Higher-and-Further-Education.aspx>
More information about the users
mailing list