shibboleth.SAML2PersistentGenerator question

Les LaCroix llacroix at carleton.edu
Sat Feb 20 00:26:36 UTC 2021


Background: I tried to upgrade an old 3.3.0 IdP to 3.4.*, which had a lot
of cruft in it from upgrades that were maybe not done well ever since the
2.* days.  It all works great, EXCEPT logging in on Windows to
MicrosoftOnline in Office apps fails about 50% of the time, and three
months of debugging with help from Unicon and Microsoft didn't solve it.
So I came at it from the opposite angle: start with a clean v4.0.1
installation (based on the TAP container) and reintroduce changes into the
v4 config.  That approach is working so far (MSOnline logins seem to work
flawlessly), EXCEPT my SAML2PersistentGenerator nameid generator isn't
producing the same results as reported by aacli.sh.

I have verified that saml-nameid.properties contains the same values
for idp.persistentId.sourceAttribute, idp.persistentId.algorithm,
and idp.persistentId.salt, and that the bean reference for
shibboleth.SAML2PersistentGenerator is present (not commented out).  I even
tried adding "idp.persistentId.encoding = BASE64" to
saml-nameid.properties, even though the newly generated value looked to be
base64 anyway (contained both upper and lower case).

I also added the source attribute to the filter for the relying party I'm
testing against, and verified that it has the value I expect.

What else might I need to do?  Thanks, -Les

<http://www.carleton.edu/>

*Les LaCroix '79*

Strategic Technologist

Information Technology Services

t: (507) 222-5455
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210219/084cf239/attachment.htm>


More information about the users mailing list