Attribute Transcoding errors following IdP upgrade

Simon McLeish simon.mcleish at gmail.com
Tue Sep 22 09:53:18 UTC 2020


Hi,

I've upgraded our 3.46 IdP to 4.0.1, and I'm getting errors where there
weren't any before, in attribute transcoding. There weren't any log
warnings about deprecated configuration before the upgrade. I'm getting
transcoding errors ("No transcoding rule for Attribute") for two attributes
(mail urn:oid:0.9.2342.19200300.100.1.3 and employeeNumber
urn:oid:2.16.840.1.113730.3.1.3) which I didn't have before, and these
attributes appear to be present in the default encoding rule set in the
inetOrgPerson.xml file. I'm also getting the errors for one login route and
not for the other: the IdP I control (call it IdP1) provides authentication
for one group of users, and a second IdP (IdP2) which I don't have control
over provides authentication for another group, both to the same SP. IdP2
doesn't provide all the attributes needed to establish access to the SP, so
for these users, the SP does a lookup to IdP1 to obtain the missing
attributes, and it is for this lookup that the encoding is failing.
Authentication solely using IdP1 is working as expected, and providing
these attributes.

Can you tell me where I should be looking in order to sort this out? I have
control over the SP involved as well, so if the answer is to look there,
that's a useful thing to know. I can't see anything in the standard logs,
and if there's anything visible when I up the level to DEBUG on the IdP,
there's so much log data I missed it.

Thanks,
Simon
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200922/1e151bbd/attachment.htm>


More information about the users mailing list