Attribute Registry vs Attribute Resolver - best practice?
Dave Perry
d.perry1 at yorksj.ac.uk
Fri Oct 11 15:02:34 UTC 2024
Hi Mark
It took some doing, but I got our IdP using AD for attributes - setting up the SAML-provided variable to map to the attribute resolver was fun, but it works.
I did all that in v4, and it survived the in-place upgrade to v5 smoothly.
Happy to go through my config next week and see what I've done (Jisc's guide on this is actually decent, I had a couple of issues where v4 config items were missing - a deployment I inherited).
Thanks
Dave
_________________________________________________
Dave Perry
Application Analyst | Innovation & Technology Services
York St John University
Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk> | www.yorksj.ac.uk<http://www.yorksj.ac.uk/>
[cid:a80532fa-8ef9-449d-b8a9-c8de32c25a5f]
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Mark Cairney via users <users at shibboleth.net>
Sent: Friday, October 11, 2024 3:48 PM
To: users at shibboleth.net <users at shibboleth.net>
Cc: Mark Cairney <Mark.Cairney at ed.ac.uk>
Subject: Attribute Registry vs Attribute Resolver - best practice?
Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
Hi,
We're now looking at moving our IdP from being standalone (behind a
REMOTE_USER variable for authentication) to using the new SAML proxy
functionality provided in V4+.
Having gone through the procedure on our Dev IdP it seems to me like
using the attribute-registry.xml is the documented method for handling
attributes coming upstream from Azure AD. [1],[2]
To do this without changing how I handle the existing attributes getting
looked up from LDAP I uncommented the
'shibboleth.AttributeRegistryResources' block in services.xml but in
attributes/default-rules.xml I've commented out everything except the
new azureClaims.xml file e.g.
<!-- Comment out everything but the additional azureClaims.xml -->
<!-- <import resource="inetOrgPerson.xml" />
<import resource="eduPerson.xml" />
<import resource="eduCourse.xml" />
<import resource="samlSubject.xml" /> -->
<import resource="azureClaims.xml" />
Is this a sensible approach for systems that have been upgraded from V3
->V4 ->V5 and will there any issues going forward? My
attribute-resolver.xml is relatively standard but does have some custom
mappings for handing Windows-style claims (pre-Azure integration) and
some mapped attributes for eduGAIN assurance purposes.
[1]
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FKB%2Fpages%2F1467056889%2FUsing%2BSAML%2BProxying%2Bin%2Bthe%2BV4%2BShibboleth%2BIdP%2Bto%2Bconnect%2Bwith%2BAzure%2BAD&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7C9ad5fdcb25ff4147099408dcea03e780%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638642549685756082%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=4x4J5X2YoLO5AR93Tqh%2FMUceKEydAEQravvhqbwHaa0%3D&reserved=0<https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1467056889/Using+SAML+Proxying+in+the+V4+Shibboleth+IdP+to+connect+with+Azure+AD>
[2]
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FKB%2Fpages%2F2783936889%2FSAML%2BProxying%2BEntraID%2BAzure%2Bwith%2Bthe%2BShibboleth%2BIdP&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7C9ad5fdcb25ff4147099408dcea03e780%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638642549685774974%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=yhFqsN9UPpsp75aOTv%2BjQGLcANbyggt1jIaeHs6yyIw%3D&reserved=0<https://shibboleth.atlassian.net/wiki/spaces/KB/pages/2783936889/SAML+Proxying+EntraID+Azure+with+the+Shibboleth+IdP>
--
/****************************
Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh
Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk
*******************************/
The University of Edinburgh is a charitable body, registered in Scotland, with registration number SC005336.
--
For Consortium Member technical support, see https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7C9ad5fdcb25ff4147099408dcea03e780%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638642549685785850%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=HRsApxZ%2FozGyMdL7hvHUn5pZo3fcu7lmeuhC1K6QL2E%3D&reserved=0<https://shibboleth.atlassian.net/wiki/x/ZYEpPw>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241011/e6ff43d5/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Outlook-bpuhuikc.png
Type: image/png
Size: 12155 bytes
Desc: Outlook-bpuhuikc.png
URL: <http://shibboleth.net/pipermail/users/attachments/20241011/e6ff43d5/attachment.png>
More information about the users
mailing list