OIDC: this user can't understand how to generate sub claim

Francesco Malvezzi francesco.malvezzi at unimore.it
Thu Sep 22 06:53:20 UTC 2022

hi everybody,

I would like to report my success in generating and releasing OIDC sub 

For nobody's surprise, the example file provided 
(etc/examples/oidc-attribute-resolver.xml) works great out-of-the-box.

My mistake was in my conf/services.xml where I couldn't figure out a 
double inclusion is needed:

  <util:list id ="shibboleth.AttributeResolverResources">

        This is suitable for new installs but will usually produce 
duplicate Attribute
         output if a legacy resolver file is used that contains 
     <util:list id ="shibboleth.AttributeRegistryResources">

If I don't include oidc-attribute-resolver.xml in both 
AttributeResolverResources and AttributeRegistryResources the flow will 
fail with "Unable to produce a viable 'sub' claim" error.



More information about the users mailing list