IDP 3.3.2 CAS protocol and alternate CAS username difficulty

Mak, David d.mak at northeastern.edu
Thu Apr 12 15:36:58 EDT 2018


I’ve hit a block and would like to see if others might be able to point me in the right direction. On a IDP 3.3.2 setup with a CAS configuration setup to release a different attribute as the name-identifier, I see log entries that show it going through the process but the payload itself doesn’t have the said attribute value as the nameid, but instead, has the login id. Here’s an example output with debugging:

2018-04-12 15:14:54,359 - DEBUG [net.shibboleth.idp.cas.flow.impl.UpdateIdPSessionWithSPSessionAction:104] - Created SP session CASSPSession: https://bnrxedevh.neu.edu/applicationNavigator/j_spring_cas_security_check via ST-1523560493949-39d7YFB7AJokyxeoqtDwFOe3u
2018-04-12 15:14:54,360 - DEBUG [net.shibboleth.idp.session.impl.StorageBackedIdPSession:433] - Ignoring SPSession add, session manager is not configured to track them

This line indicates to me that the relaying party config to override the CAS username is triggered for this end-point:
2018-04-12 15:14:54,360 - DEBUG [net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction:88] - Using neuEduNUID for CAS username

The following shows the attributes and values (some sanitized for privacy), with the attribute name/value being: neuEduNUID=MYNUID:
2018-04-12 15:14:54,360 - DEBUG [net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction:107] - Processing IdPAttribute{id=commonName, displayNames={}, displayDescriptions={}, encoders=[net.shibboleth.idp.saml.attribute.encoding.impl.SAML1StringAttributeEncoder at 355ef6be, net.shibboleth.idp.saml.attribute.encoding.impl.SAML2StringAttributeEncoder at d1644fc9], values=[StringAttributeValue{value=David Mak}]}
2018-04-12 15:14:54,361 - DEBUG [net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction:107] - Processing IdPAttribute{id=eduPersonScopedAffiliation, displayNames={}, displayDescriptions={}, encoders=[net.shibboleth.idp.saml.attribute.encoding.impl.SAML2StringAttributeEncoder at 23ac74, net.shibboleth.idp.saml.attribute.encoding.impl.SAML1StringAttributeEncoder at bab64ea8], values=[StringAttributeValue{value=staff at neu.edu}, StringAttributeValue{value=member at neu.edu}]}
2018-04-12 15:14:54,361 - DEBUG [net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction:107] - Processing IdPAttribute{id=UDC_IDENTIFIER, displayNames={}, displayDescriptions={}, encoders=[net.shibboleth.idp.saml.attribute.encoding.impl.SAML2StringAttributeEncoder at 8c4162f2, net.shibboleth.idp.saml.attribute.encoding.impl.SAML1StringAttributeEncoder at 27b56b59], values=[StringAttributeValue{value=UDCIDVALUE}]}
2018-04-12 15:14:54,361 - DEBUG [net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction:107] - Processing IdPAttribute{id=neuEduNUID, displayNames={}, displayDescriptions={}, encoders=[net.shibboleth.idp.saml.attribute.encoding.impl.SAML1StringAttributeEncoder at 44856ed, net.shibboleth.idp.saml.attribute.encoding.impl.SAML2StringAttributeEncoder at fb415ce], values=[StringAttributeValue{value=MYNUID}]}
2018-04-12 15:14:54,361 - DEBUG [net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction:107] - Processing IdPAttribute{id=eduPersonPrincipalName, displayNames={}, displayDescriptions={}, encoders=[net.shibboleth.idp.saml.attribute.encoding.impl.SAML2ScopedStringAttributeEncoder at 23a131, net.shibboleth.idp.saml.attribute.encoding.impl.SAML1ScopedStringAttributeEncoder at 5625d981], values=[ScopedStringAttributeValue{value=MYNUID, scope=neu.edu}]}
2018-04-12 15:14:54,362 - INFO [Shibboleth-Audit.SSO:275] - 20180412T191454Z|||https://bnrxedevh.neu.edu/applicationNavigator/j_spring_cas_security_check|https://www.apereo.org/cas/protocol/serviceValidate||||MYLOGINID||commonName,eduPersonScopedAffiliation,UDC_IDENTIFIER,neuEduNUID,eduPersonPrincipalName|MYLOGINID|ST-1523560493949-39d7YFB7AJokyxeoqtDwFOe3u|

Here's the payload:
2018-04-12 15:14:54,362 - DEBUG [net.shibboleth.idp.cas.flow.impl.BuildSamlValidationSuccessMessageAction:113] - Building SAML response for https://bnrxedevh.neu.edu/applicationNavigator/j_spring_cas_security_check in IdP session 8c42f2c1790bae2cc80fc0c8920a2c48ac006c6d327ab71f0e0f622405ef3260
2018-04-12 15:14:54,364 - DEBUG [net.shibboleth.idp.saml.profile.impl.SpringAwareMessageEncoderFactory:100] - Looking up message encoder based on binding URI: urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding
2018-04-12 15:14:54,368 - DEBUG [PROTOCOL_MESSAGE:70] -
<?xml version="1.0" encoding="UTF-8"?>
<SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">
    <SOAP-ENV:Body>
        <saml1p:Response IssueInstant="2018-04-12T19:14:54.362Z"
            MajorVersion="1" MinorVersion="1"
            ResponseID="ST-1523560493949-39d7YFB7AJokyxeoqtDwFOe3u" xmlns:saml1p="urn:oasis:names:tc:SAML:1.0:protocol">
            <saml1p:Status>
                <saml1p:StatusCode Value="saml1p:Success"/>
            </saml1p:Status>
            <saml1:Assertion
                AssertionID="_753381667db3444d73b6c09981d00952"
                IssueInstant="2018-04-12T19:14:54.362Z"
                Issuer="https://neuidmssodev.neu.edu/idp/shibboleth"
                MajorVersion="1" MinorVersion="1" xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion">
                <saml1:Conditions NotBefore="2018-04-12T19:14:54.362Z" NotOnOrAfter="2018-04-12T19:15:54.362Z">
                    <saml1:AudienceRestrictionCondition>
                        <saml1:Audience>https://bnrxedevh.neu.edu/applicationNavigator/j_spring_cas_security_check</saml1:Audience>
                    </saml1:AudienceRestrictionCondition>
                </saml1:Conditions>
                <saml1:AuthenticationStatement
                    AuthenticationInstant="2018-04-12T19:14:54.362Z" AuthenticationMethod="authn/MFA">
                    <saml1:Subject>
                        <saml1:NameIdentifier>MYLOGINID</saml1:NameIdentifier>
                        <saml1:SubjectConfirmation>
                            <saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod>
                        </saml1:SubjectConfirmation>
                    </saml1:Subject>
                </saml1:AuthenticationStatement>
                <saml1:AttributeStatement>
                    <saml1:Subject>
                        <saml1:NameIdentifier>MYLOGINID</saml1:NameIdentifier>
                        <saml1:SubjectConfirmation>
                            <saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod>
                        </saml1:SubjectConfirmation>
                    </saml1:Subject>
                    <saml1:Attribute AttributeName="commonName" AttributeNamespace="http://www.ja-sig.org/products/cas/">
                        <saml1:AttributeValue
                            xmlns:xsd="http://www.w3.org/2001/XMLSchema"
                            xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">David Mak</saml1:AttributeValue>
                    </saml1:Attribute>
                    <saml1:Attribute
                        AttributeName="eduPersonScopedAffiliation" AttributeNamespace="http://www.ja-sig.org/products/cas/">
                        <saml1:AttributeValue
                            xmlns:xsd="http://www.w3.org/2001/XMLSchema"
                            xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">staff at neu.edu</saml1:AttributeValue>
                        <saml1:AttributeValue
                            xmlns:xsd="http://www.w3.org/2001/XMLSchema"
                            xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">member at neu.edu</saml1:AttributeValue>
                    </saml1:Attribute>
                    <saml1:Attribute AttributeName="UDC_IDENTIFIER" AttributeNamespace="http://www.ja-sig.org/products/cas/">
                        <saml1:AttributeValue
                            xmlns:xsd="http://www.w3.org/2001/XMLSchema"
                            xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">EEE3939EB1DA663B727990E33CDE7F1A</saml1:AttributeValue>
                    </saml1:Attribute>
                    <saml1:Attribute AttributeName="neuEduNUID" AttributeNamespace="http://www.ja-sig.org/products/cas/">
                        <saml1:AttributeValue
                            xmlns:xsd="http://www.w3.org/2001/XMLSchema"
                            xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">MYNUID</saml1:AttributeValue>
                    </saml1:Attribute>
                    <saml1:Attribute
                        AttributeName="eduPersonPrincipalName" AttributeNamespace="http://www.ja-sig.org/products/cas/">
                        <saml1:AttributeValue
                            xmlns:xsd="http://www.w3.org/2001/XMLSchema"
                            xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">MYNUID</saml1:AttributeValue>
                    </saml1:Attribute>
                </saml1:AttributeStatement>
            </saml1:Assertion>
        </saml1p:Response>
    </SOAP-ENV:Body>
</SOAP-ENV:Envelope>

This is the saml-nameid.xml snippet for that attribute:
    <util:list id="shibboleth.SAML1NameIdentifierGenerators">

        <ref bean="shibboleth.SAML1TransientGenerator" />

        <bean parent="shibboleth.SAML1AttributeSourcedGenerator"
            p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
            p:attributeSourceIds="#{ {'neuEduNUID'} }" />

    </util:list>

Thank you in advance.

David Mak
Identity Services Specialist
Information Technology Services
Northeastern University
360 Huntington Ave. Boston MA 02115-5000
Mail Stop: 322-C21
Office: 617-373-7836 Mobile: 617-840-7543
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180412/b7a0d058/attachment.html>


More information about the users mailing list