Duplicate values for EPPN coming from multiple federation release sets

Cooper, Robert A racooper at tamu.edu
Thu Nov 7 22:21:24 UTC 2024


Howdy!
I'm trying to troubleshoot an issue where a SP is receiving multiple values for EPPN, apparently due to being members of both InCommon and Research and Scholarship (refed) federations.  InCommon receives a subset of the same attributes being released to refed, and the values for eduPersonPrincipalName are being merged so it returns two values.

EPPN=user at site.edu;user at site.edu

We have had similar cases in the past, where the solution was to set a DenyValueRule for the duplicated attribute - but in that case, the SP was receiving from InCommon and an explicit release for the SP, not from two different federations.  Trying the deny rule this time, it completely removed the EPPN from the release data.

To complicate things even more, the SP is using a Cirrus IDP Proxy, which I know nothing about, and don't have any idea how it might be manipulating the release data.

Is there some way to prioritize the R&S release so that if it is in use, the InCommon release is ignored?  That was the suggestion from the admin for the SP that's having this issue.  Otherwise, is there some other solution that I can implement for this kind of situation?  My grasp of the details of shibboleth is... shall we say lacking, when it comes to how all the federation setup works.

Thanks,
Robert Cooper

--
Robert A. Cooper | Senior Lead Infrastructure Systems Engineer
Infrastructure Systems Operations | Technology Services
Texas A&M University
1368 TAMU | College Station, TX 77843-1368
ph: 979-862-1262 | racooper at tamu.edu
IT.tamu.edu

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241107/3a5aa2a2/attachment.htm>


More information about the users mailing list