Missing Attributes

IAM David Bantz dabantz at alaska.edu
Fri Jun 15 11:04:19 EDT 2018


I think you need the explicit Dependency on the source attribute:

Assuming eduPersonAffiliaiton is properly defined elsewhere in
attribute-resolver.

    <AttributeDefinition id="eduPersonScopedAffiliation" xsi:type="Scoped"

        scope="alaska.edu" sourceAttributeID="eduPersonAffiliation">

        *<Dependency ref="eduPersonAffiliation" />*


      <AttributeEncoder xsi:type="SAML1ScopedString"

            name="urn:mace:dir:attribute-def:eduPersonScopedAffiliation" />


      <AttributeEncoder xsi:type="SAML2ScopedString"

            name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" friendlyName=
"eduPersonScopedAffiliation" />

    </AttributeDefinition>

Sorry I muddied the water with mention of "transient" - I should have
written "targeted":
The idea of targeted id is that to be a different value for every SP,
preserving some element of privacy because it doesn't support directly
correlating an individual user's activity between SPs.
So a properly defined targeted id is not going to be a static value from
your attribute store, it's going to be ginned up from some source value but
deliberately have a different value for each different SP.

Hope this helps.

David Bantz

On Fri, Jun 15, 2018 at 6:20 AM, Thermal Reboot <thermalreboot at gmail.com>
wrote:

> I'm hardly an expert and I'm desperately trying to get my head around
> these concepts, I wish there were an Oreilly book on Shibboleth as I find
> the website very dry and assumes you know what you want to do.
>
> Here is what I have in attribute-resolver.xml, I assume that's what you
> want.
>
>     <resolver:AttributeDefinition xsi:type="ad:Scoped" id="eduPersonScopedAffiliation"
> scope="%{idp.scope}" sourceAttributeID="eduPersonAffiliation">
>         <resolver:Dependency ref="myLDAP" />
>         <resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString"
> name="urn:mace:dir:attribute-def:eduPersonScopedAffiliation"
> encodeType="false" />
>         <resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString"
> name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" friendlyName="eduPersonScopedAffiliation"
> encodeType="false" />
>     </resolver:AttributeDefinition>
>
> As for the eduPersonTargetedID sending a transient, it's a mystery to me.
>
> Here's my attribute-resolver.xml entry for that:
>
> <resolver:AttributeDefinition xsi:type="ad:SAML2NameID"
> id="eduPersonTargetedID"
>     nameIdFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
> sourceAttributeID="computedID">
>     <resolver:Dependency ref="computedID" />
>     <resolver:AttributeEncoder xsi:type="enc:SAML1XMLObject"
> name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" />
>     <resolver:AttributeEncoder xsi:type="enc:SAML2XMLObject"
> name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" friendlyName="eduPersonTargetedID"
> />
> </resolver:AttributeDefinition>
>
>
> Thanks
> -Bob
>
> On Thu, Jun 14, 2018 at 6:22 PM, IAM David Bantz <dabantz at alaska.edu>
> wrote:
>
>> An attribute with null value - as explicitly indicated in your log
>> snippet - will not be sent.
>>
>> You don't include the attribute resolver definition but the earlier log
>> entry indicates an LDAP value of "Staff" which is not scoped.
>>
>> I'm not at all clear what you're trying to do in attempting to release a
>> "transient" identifier that has the persistent (i.e., non-transient) value
>> of a directory attribute - isn't that a category mis-match?
>>
>> David Bantz
>>
>> On Thu, Jun 14, 2018 at 11:48 AM, Thermal Reboot <thermalreboot at gmail.com
>> > wrote:
>>
>>> Hello,
>>>
>>>     I have an SP that requires eduPersonScopedAffiliation and
>>> eduPersonTargetedID.  To test this I setup my attribute-filter.xml files to
>>> deliver these two attributes to sp.testshib.org, but neither of them
>>> are being delivered.
>>>
>>>     I've verified that both attributes are populated in AD and can see
>>> that they're being delivered by LDAP:
>>>
>>> 2018-06-14 15:00:50,193 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.AbstractDataConnector:143] - Data Connector 'myLDAP':
>>> Attribute 'eduPersonScopedAffiliation': Values
>>> '[StringAttributeValue{value=Staff}]'
>>>
>>> 2018-06-14 15:00:50,194 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.AbstractDataConnector:143] - Data Connector 'myLDAP':
>>> Attribute 'eduPersonTargetedID': Values '[StringAttributeValue{value=l
>>> amother}]'
>>>
>>> Yet I also see this:
>>>
>>> 2018-06-14 10:21:50,312 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:372] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Resolving dependencies for
>>> 'eduPersonScopedAffiliation'
>>> 2018-06-14 10:21:50,312 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:388] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Finished resolving dependencies for
>>> 'eduPersonScopedAffiliation'
>>> 2018-06-14 10:21:50,312 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.AbstractAttributeDefinition:245] - Attribute Definition
>>> 'eduPersonScopedAffiliation': produced an attribute with no values
>>> 2018-06-14 10:21:50,313 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:272] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Attribute definition
>>> 'eduPersonScopedAffiliation' produced an attribute with 0 values
>>> 2018-06-14 10:21:50,353 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:428] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Removing result of attribute definition
>>> 'eduPersonScopedAffiliation', contains no values
>>>
>>>
>>> And
>>>
>>> 2018-06-14 15:00:50,261 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:372] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Resolving dependencies for
>>> 'eduPersonTargetedID'
>>> 2018-06-14 15:00:50,264 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:388] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Finished resolving dependencies for
>>> 'eduPersonTargetedID'
>>> 2018-06-14 15:00:50,276 - DEBUG [net.shibboleth.idp.saml.attri
>>> bute.resolver.impl.SAML2NameIDAttributeDefinition:153] - Attribute
>>> Definition 'eduPersonTargetedID': building a SAML2 NameID with value of
>>> 'XgQzYSIOcCKtS8gcaeSXYCyfsfE='
>>> 2018-06-14 15:00:50,276 - DEBUG [net.shibboleth.idp.saml.attri
>>> bute.resolver.impl.SAML2NameIDAttributeDefinition:164] - Attribute
>>> Definition 'eduPersonTargetedID': Format set to
>>> 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent'
>>> 2018-06-14 15:00:50,277 - DEBUG [net.shibboleth.idp.saml.attri
>>> bute.resolver.impl.SAML2NameIDAttributeDefinition:172] - Attribute
>>> Definition 'eduPersonTargetedID': NameQualifier set to '
>>> https://testshib.umassmed.edu/idp/shibboleth'
>>> 2018-06-14 15:00:50,277 - DEBUG [net.shibboleth.idp.saml.attri
>>> bute.resolver.impl.SAML2NameIDAttributeDefinition:182] - Attribute
>>> Definition 'eduPersonTargetedID': SPNameQualifier set to '
>>> https://sp.testshib.org/shibboleth-sp'
>>> 2018-06-14 15:00:50,278 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.AbstractAttributeDefinition:247] - Attribute Definition
>>> 'eduPersonTargetedID': produced an attribute with the following values
>>> [XMLObjectAttributeValue{value=org.opensaml.saml.saml2.core.
>>> impl.NameIDImpl at d7124d8}]
>>> 2018-06-14 15:00:50,278 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:272] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Attribute definition 'eduPersonTargetedID'
>>> produced an attribute with 1 values
>>> 2018-06-14 15:00:50,366 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:434] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': De-duping attribute definition
>>> eduPersonTargetedID result
>>> 2018-06-14 15:00:50,366 - DEBUG [net.shibboleth.idp.attribute.
>>> resolver.impl.AttributeResolverImpl:446] - Attribute Resolver
>>> 'ShibbolethAttributeResolver': Attribute 'eduPersonTargetedID' has 1 values
>>> after post-processing
>>>
>>>
>>> My decrypted Assertion at sp.testshib.org looks like:
>>>
>>> 2018-06-14 15:41:49 DEBUG Shibboleth.SSO.SAML2 [76]: decrypted Assertion: <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_f8ee0b26b509a4840675be141cefd1f0" IssueInstant="2018-06-14T19:41:48.238Z" Version="2.0"><saml2:Issuer>https://testshib.umassmed.edu/idp/shibboleth</saml2:Issuer><saml2:Subject><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="https://testshib.umassmed.edu/idp/shibboleth" SPNameQualifier="https://sp.testshib.org/shibboleth-sp" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">AAlzZWNyZXQ4ODZCiDJKa7lVg5ZzS4KC9fJRKm/5M3zTvK1kZ6/O2iqrEfMDjzNgTuD0OlQEQgXQdq/CSEVuJmHIAy7+eFJ4bgYz80Znlp0oMPad2nyuLIxI3xqZOIP31dMgqHCaWmYzNvCpG4LL0W5InfUv</saml2:NameID><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData Address="146.189.148.19" InResponseTo="_d3f4f0823fe28c735d62a9ed6d717552" NotOnOrAfter="2018-06-14T19:46:48.364Z" Recipient="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions NotBefore="2018-06-14T19:41:48.238Z" NotOnOrAfter="2018-06-14T19:46:48.238Z"><saml2:AudienceRestriction><saml2:Audience>https://sp.testshib.org/shibboleth-sp</saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement AuthnInstant="2018-06-14T19:41:39.175Z" SessionIndex="_881534154dad964ab5923b2ec0e9e355"><saml2:SubjectLocality Address="146.189.148.19"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement><saml2:AttributeStatement><saml2:Attribute FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>LamotheR</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonPrimaryAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Staff</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Robert.Lamothe at umassmed.edu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://testshib.umassmed.edu/idp/shibboleth" SPNameQualifier="https://sp.testshib.org/shibboleth-sp">XgQzYSIOcCKtS8gcaeSXYCyfsfE=</saml2:NameID></saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Lamothe, Robert L</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Lamothe</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Robert</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>lamother at umassmed.edu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="title" Name="urn:oid:2.5.4.12" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Sr Eng, Sys Admin</saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement>
>>> </saml2:AttributeStatement></saml2:Assertion>
>>>
>>> In the Assertion I see eduPersonTargetedID which looks like it's being set to NameID instead of the AD value,
>>>
>>> yet I don't see eduPersonScopedAffiliation.
>>>
>>> Am I miss understanding something?  Is my config messed up?
>>>
>>> Thanks
>>>
>>> -Bob
>>>
>>>
>>> --
>>> For Consortium Member technical support, see
>>> https://wiki.shibboleth.net/confluence/x/coFAAg
>>> To unsubscribe from this list send an email to
>>> users-unsubscribe at shibboleth.net
>>>
>>
>>
>> --
>> For Consortium Member technical support, see
>> https://wiki.shibboleth.net/confluence/x/coFAAg
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180615/6b4ec70b/attachment.html>


More information about the users mailing list