Duplicate values for EPPN coming from multiple federation release sets

Steven Premeau steven.premeau at maine.edu
Thu Nov 7 22:54:36 UTC 2024


Robert -

 I have seen this when I had multiple internal attribute resolver IDs
defining EPPN.  (In my case it was different values as I worked to
transition from a legacy "bad" EPPN value to a proper stable one.)

 If both releases are working with the same attribute resolver attribute
ID, it's possible that you've had this issue in other places, but the
Cirrus Proxy is (correctly) interpreting things in ways most of your SPs
don't bother to do.

   Assuming the included aacli utility
<https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199511404/AACLI> is
usable in your environment, does it display the attribute twice (when you
use the --saml2 option)?

  If so (and this is the same single attribute ID, this recent thread may
be of use -- https://shibboleth.net/pipermail/users/2024-October/055718.html

Steve.

On Thu, Nov 7, 2024 at 5:28 PM Cantor, Scott via users <users at shibboleth.net>
wrote:

> If you're asking about the IdP and its filtering rules, you don't end up
> asserting the same value twice because two different rules permit a value.
>
> Additionally, the IdP de-dups coming out of the resolver to begin with.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241107/04efab04/attachment.htm>


More information about the users mailing list