Shibboleth IDP 3 and Onelogin PHP SAML library
Richard Genthner
richard at guthnur.net
Wed Jun 21 12:23:22 EDT 2017
Has anyone used Shibboleth IDP 3 and the onelogin PHP SAML Library? We are
trying to get it working for requesting the email attribute with the
formatting of urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress but
i'm getting this in the logs:
2017-06-21 16:02:17,521 - DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:116]
- Profile Action AddAttributeStatementToAssertion: Adding constructed
AttributeStatement to Assertion _2d5c96c50591b2ce8f913870584a02eb
2017-06-21 16:02:17,545 - DEBUG
[org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:286] - Profile
Action AddNameIDToSubjects: Attempting to add NameID to outgoing Assertion
Subjects 2017-06-21 16:02:17,545 - DEBUG
[org.opensaml.saml.common.profile.logic.AbstractNameIDPolicyPredicate:218]
- Policy checking disabled for NameIDPolicy with Format
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress 2017-06-21
16:02:17,545 - DEBUG
[org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:316] - Profile
Action AddNameIDToSubjects: Request specified NameID format:
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress 2017-06-21
16:02:17,546 - DEBUG
[org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:396] - Profile
Action AddNameIDToSubjects: Trying to generate NameID with Format
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress 2017-06-21
16:02:17,549 - DEBUG
[org.opensaml.saml.common.profile.impl.ChainingNameIdentifierGenerator:106]
- Trying to generate identifier with Format
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress 2017-06-21
16:02:17,549 - WARN
[org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:337] - Profile
Action AddNameIDToSubjects: Request specified use of an unsupportable
identifier format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
2017-06-21 16:02:17,551 - WARN
[org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event
occurred while processing the request: InvalidNameIDPolicy 2017-06-21
16:02:17,551 - DEBUG
[org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:184] -
Error event InvalidNameIDPolicy will be handled with response
2017-06-21 16:02:17,582 - DEBUG
[net.shibboleth.idp.saml.profile.impl.SpringAwareMessageEncoderFactory:100]
- Looking up message encoder based on binding URI:
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
2017-06-21 16:02:17,582 - DEBUG
[org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:159] -
Invoking Velocity template to create POST body
2017-06-21 16:02:17,582 - DEBUG
[org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:192] -
Encoding action url of 'https://app.*****/rest/saml/auth/682879' with
encoded value 'https://app.wheniwork.com
/rest/saml/auth/682879'
2017-06-21 16:02:17,583 - DEBUG
[org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:198] -
Marshalling and Base64 encoding SAML message
2017-06-21 16:02:17,584 - DEBUG
[org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:220] -
Setting RelayState parameter to: 'https://app.*****/rest/saml/sso/682879',
encoded as 'https://deltaems.wheniwork.com
/rest/saml/sso/682879'
2017-06-21 16:02:17,619 - DEBUG [PROTOCOL_MESSAGE:70] -
<?xml version="1.0" encoding="UTF-8"?>
<saml2p:Response
Destination="https://app.*****/rest/saml/auth/682879"
ID="_287de7299ff7144786bdcbfc581aaae4"
InResponseTo="ONELOGIN_dddba38cfe08ca53c64103a8dbd6ff8baa05330e"
IssueInstant="2017-06-21T16:02:17.552Z" Version="2.0"
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol">
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
https://ec2-52-205-175-9.compute-1.amazonaws.com/idp/shibboleth
</saml2:Issuer>
<ds:Signature
xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
"/>
<ds:Reference
URI="#_287de7299ff7144786bdcbfc581aaae4">
<ds:Transforms>
<ds:Transform
Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>WN33K1jzNaKquXb3/MNE9yKkv+rxxr9kaktp1b07nKk=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
mBFhQFTAWEQiGk+j0IBVOy+qieXKl3zeoUlPumOdvjei9GFgZpaJO8B8RXkIMXyI5lAwF8ckkTPZ
suHZq1Il6xw9tLUmIREX64MGPfaJG3np8p+EG4UjpsIFV/6hNx8h9GJeAHjeua+4GCoJc9RKHuzB
EHAnmWCW9zDBfWCn/yz+1ERKfRmdNxOFIZDzdRUV4gBDPdtuvEdQ3+g8BpYg8ho8bQ9Zdf/JsJ1k
VjU6x8qwmJ8OmbKR5KHQg2vACt3Y66mmVSMmQWxx6B6J6QJcc0UTSqj1jlm5pKb0bwKsBo163hhI
JGe0pmR4STy7+RVGSC4oeUtity8OBnQE/LU06g==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIDjjCCAnagAwIBAgIVALZXVrIMahjLPgP5zCZ919nEWgKOMA0GCSqGSIb3DQEBCwUAMDMxMTAv
BgNVBAMMKGVjMi01Mi0yMDUtMTc1LTkuY29tcHV0ZS0xLmFtYXpvbmF3cy5jb20wHhcNMTcwNjIx
MTM1NDQyWhcNMzcwNjIxMTM1NDQyWjAzMTEwLwYDVQQDDChlYzItNTItMjA1LTE3NS05LmNvbXB1
dGUtMS5hbWF6b25hd3MuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxdoGde96
+X7wsvaLgq/KIxDchSpBVCqaeaKMoZdaHZEoebVQI0NV0F845hCsLMauLAr1q3MpqPsPcbMflZ0F
y9fjP09ytGrB3R+0qbv1pqo+Fgc1XQKuAzQHNQjnJv2apA4fZdfe0PAa4T30aomGHnvAeZkwLAC7
aDnBTmYc9z4TysAPR+F6hTiBxyXpKzAsSC0+pTQI9Ed7/DwsRhY314QJL5FijLNSJxSyL0Z+JXq1
ZrK/EKr6G4d1jazeGm91Vo0YGKtoCoWwa9hXAg59LRY42sJcH3h0arZb8FnJLSbL2rDb9LyhBKgQ
x2zxmQCyhTK433iYeW36YogCrHws9QIDAQABo4GYMIGVMB0GA1UdDgQWBBRagN8EDWrdIixZXZ3M
U7XK1ThEzDB0BgNVHREEbTBrgihlYzItNTItMjA1LTE3NS05LmNvbXB1dGUtMS5hbWF6b25hd3Mu
Y29thj9odHRwczovL2VjMi01Mi0yMDUtMTc1LTkuY29tcHV0ZS0xLmFtYXpvbmF3cy5jb20vaWRw
L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBACK8wHHT0CCS738sSrovXLDsXzjPsQlLy+EE
BKzewpLEBh/Yu28d3AerbCqwfS9D3YDcIOcjCHSqVyU0ewaVZ2Iq1bo4ov+9B8EJb76lPX+YnnIr
/rHsQJygl7d7BzJchmSh8YJknKlfmxMfxCMNVuVo/3Q+K0vQeXxZQ5svLlFgSdGRSaTLO6UQqp2M
3uDs6SwsGDR+CpiUyke1wAcnBzVzMQ6lpRopylM1//mCi7pOmFBcG0e1qUeXRcp8nh/DYqpchind
w007/vN1hpEyhILhPW/xQgMcvxkdCJMsPYuM2U0GHQzP6AzY4LLXdIAK2icxY/prCd+u/CFWVqft
Qt0=</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2p:Status>
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy"/>
</saml2p:StatusCode>
<saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage>
</saml2p:Status>
</saml2p:Response>
2017-06-21 16:02:17,620 - DEBUG
[net.shibboleth.idp.profile.impl.RecordResponseComplete:89] - Profile
Action RecordResponseComplete: Record response complete
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170621/6254d9ad/attachment-0001.html>
More information about the users
mailing list