unspecified nameid Brightspace LMS
Lipscomb, Gary
glipscomb at csu.edu.au
Thu Apr 20 06:20:52 UTC 2023
Hi all,
I got it working
Removed from metadata
<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>
Added to saml-nameid.xml
<!-- nameid-format:unspecified, released to specific SP from attribute-filter.xml -->
<bean parent="shibboleth.SAML2AttributeSourcedGenerator"
p:omitQualifiers="true"
p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
p:attributeSourceIds="#{ {'attrAsNameID'} }">
</bean>
Regards
Gary
Gary Lipscomb
Technical Officer, Systems
IT Infrastructure & Security | Division of Information Technology
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Lipscomb, Gary via users
Sent: Thursday, 20 April 2023 15:39
To: Shib Users <users at shibboleth.net>
Cc: Lipscomb, Gary <glipscomb at csu.edu.au>
Subject: unspecified nameid Brightspace LMS
Hi list,
I'm trying to configure SSO for the Brightspace LMS and not having any success.
Their requirements are
The data sent in the Subject Name Identifier must be formatted as unspecified (urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified, urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified, or format not provided). This formatting must be set within your Identity Provider application settings.
Your SAML assertion must be signed using RSA SHA-256 signature. This must be set within your Identity Provider application.
I've tried using a persistent nameid as the first choice but failed.
Their logging is pathetic and intermittent. - error Subject's NameID was null.
Our environment
# /opt/shibboleth-idp/bin/status.sh
### Operating Environment Information
operating_system: Linux
operating_system_version: 4.18.0-425.3.1.el8.x86_64
jdk_version: 11.0.18
### Identity Provider Information
idp_version: 4.3.1
I am trying to use metadata attributes to allow the unspecified nameid
<mdattr:EntityAttributes>
<!-- Replaces overrrides in RelyingParty.xml -->
<saml:Attribute Name="https://aus01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fshibboleth.net%2Fns%2Fprofiles%2Fsaml2%2Fsso%2Fbrowser%2FsignResponses&data=05%7C01%7Cglipscomb%40csu.edu.au%7C0b402dce1bce4415a31c08db41619143%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638175659534572273%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=KEF88%2Bcq72S5s4yAZzMSds5OfLYyispJdmCIO1ZmwIE%3D&reserved=0"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue xsi:type="xsd:boolean">true</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="https://aus01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fshibboleth.net%2Fns%2Fprofiles%2Fsaml2%2Fsso%2Fbrowser%2FsignAssertions&data=05%7C01%7Cglipscomb%40csu.edu.au%7C0b402dce1bce4415a31c08db41619143%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638175659534572273%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=JIk9MHmovDfGTs2BxnTjeFfE41iTHt0%2BwWqbOZfGS%2BQ%3D&reserved=0"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue xsi:type="xsd:boolean">false</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="https://aus01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fshibboleth.net%2Fns%2Fprofiles%2Fsaml2%2Fsso%2Fbrowser%2FencryptAssertions&data=05%7C01%7Cglipscomb%40csu.edu.au%7C0b402dce1bce4415a31c08db41619143%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638175659534728952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=MoVX3of3ZRIU1NkiyfelmjmfCU7TykXHKWNHCjBoIL8%3D&reserved=0"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue xsi:type="xsd:boolean">false</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="https://aus01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fshibboleth.net%2Fns%2Fprofiles%2Fsaml2%2Fsso%2Fbrowser%2FencryptAttributes&data=05%7C01%7Cglipscomb%40csu.edu.au%7C0b402dce1bce4415a31c08db41619143%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638175659534728952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Kh7m1Ea5NVltR1BhC4ANDqXihST16WgNh54z2ZUPQug%3D&reserved=0"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue xsi:type="xsd:boolean">false</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="https://aus01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fshibboleth.net%2Fns%2Fprofiles%2Fsaml2%2Fsso%2Fbrowser%2FencryptNameIDs&data=05%7C01%7Cglipscomb%40csu.edu.au%7C0b402dce1bce4415a31c08db41619143%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638175659534728952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=JiD2XUxf7vMR%2FyjhJgy2Q0zft%2FSnp4zFCR%2Ft2hrlgZ8%3D&reserved=0"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue xsi:type="xsd:boolean">false</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute Name="https://aus01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fshibboleth.net%2Fns%2Fprofiles%2FnameIDFormatPrecedence&data=05%7C01%7Cglipscomb%40csu.edu.au%7C0b402dce1bce4415a31c08db41619143%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638175659534728952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=mrILZr4XRTUMA2dYUU7w1GGBgk4wOqLamEBm%2BNbJXH0%3D&reserved=0"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</saml:AttributeValue>
</saml:Attribute>
</mdattr:EntityAttributes>
<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>
The Authn Request doesn't specify a nameid.
My IdP logs are showing that the unspecified nameid has been rejected
2023-04-20 15:16:23,820 - 127.0.0.1 - WARN [org.opensaml.saml.common.profile.logic.MetadataNameIdentifierFormatStrategy:73] - Ignoring NameIDFormat metadata that includes the 'unspecified' format
Have I missed something in the configuration
regards
Gary
Technical Officer, Systems
IT Infrastructure & Security | Division of Information Technology Charles Sturt University
| ALBURY-WODONGA | BATHURST | CANBERRA | DUBBO | GOULBURN | ORANGE | PARRAMATTA | PORT MACQUARIE | WAGGA WAGGA |
LEGAL NOTICE
This email (and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in reliance on it or disclose it to anyone. Any confidentiality is not waived or lost by reason of mistaken delivery. Email should be checked for viruses and defects before opening. Charles Sturt University does not accept liability for viruses or any consequence which arise as a result of this email transmission. Email communications with Charles Sturt University may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at Charles Sturt University. The views expressed in this email are not necessarily those of Charles Sturt University.
Charles Sturt University in Australia The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551). Charles Sturt University - TEQSA Provider Identification: PRV12018 (Australian University). CRICOS Provider: 00005F.
Consider the environment before printing this email.
--
For Consortium Member technical support, see https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cglipscomb%40csu.edu.au%7C0b402dce1bce4415a31c08db41619143%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638175659534728952%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=D%2FXCrscsPclX3iQaIhjkyIZJ1ttcQCJeV9SzgoIiYuo%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list