Azure & IdP v5.1.3
Dave Perry
d.perry1 at yorksj.ac.uk
Thu Nov 7 13:59:31 UTC 2024
I made this work under our v4.3 instance - it upgraded cleanly to v5 a couple of months ago:
https://www.ukfederation.org.uk/content/Documents/Setup4IdP#Azure
There were only a couple of things that stopped this working for me on v4, but they were issues with the configuration that I inherited (properties missing in idp.properties I think).
HTH
Dave
_________________________________________________
Dave Perry
Application Analyst | Innovation & Technology Services
York St John University
Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk> | www.yorksj.ac.uk<http://www.yorksj.ac.uk/>
[cid:d28c4dfa-c27c-47b0-888f-9b01a4e38dab]
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott via users <users at shibboleth.net>
Sent: Thursday, November 7, 2024 1:07 PM
To: users at shibboleth.net <users at shibboleth.net>
Cc: Cantor, Scott <cantor.2 at osu.edu>
Subject: Re: Azure & IdP v5.1.3
Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
List please, which is what Reply-To is set to.
> The problem may be with the REGEXP.
The problem is with your metadata by definition, that's what the filter rule removing the value does. Once the value is gone, c14n is impossible, it doesn't matter what the subsequrnt
> idp.c14.saml.proxy.regex.for.principal
> =^(.+)@NAME_SERVICE\.DOMAIN\.ORGANIZATION\.br$"
That is not a setting we define in the IdP (that I recognize anyway) and I've no idea what it's doing, but it isn't relevant to an attribute filter rule enforcing scoping based on metadata.
The filter rule doesn't have any configuration settings at all, it's implicit: Check attribute values are scoped and that the scope matches the metadata extension in the issuer's metadata.
-- Scott
--
For Consortium Member technical support, see https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7C6fa20649870243cd483708dcff2dd0ad%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638665819459203044%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=2ITbBSzM44Rk%2B%2FDKJrULclzGmvBP3QUpBtBrpDlGJUs%3D&reserved=0<https://shibboleth.atlassian.net/wiki/x/ZYEpPw>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241107/432b76d3/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Outlook-aa2rmtta.png
Type: image/png
Size: 12155 bytes
Desc: Outlook-aa2rmtta.png
URL: <http://shibboleth.net/pipermail/users/attachments/20241107/432b76d3/attachment.png>
More information about the users
mailing list