Shibboleth IdP is partially working with LDAP, but SAMLResponse NameID (and attributes) are missing
o haya
ohaya1001 at gmail.com
Wed Apr 9 15:31:11 UTC 2025
Hi,
Here's what the SAMLResponse I am seeing looks like (sorry for the
obfuscations):
<?xml version="1.0" encoding="UTF-8"?><saml2p:Response
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="
https://yyy/fed/v1/sp/sso" ID="_d14919a3c5d9e2cc8455440f4f7443a6"
InResponseTo="id-IgJu6hZAQMJmcaOUKpIS7nGx2gY-"
IssueInstant="2025-04-09T13:58:19.437Z" Version="2.0">
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
https://idp01.xxxx.com/idp/shibboleth</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="
http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#_d14919a3c5d9e2cc8455440f4f7443a6">
<ds:Transforms>
<ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="
http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>TPt9U+iX0uSYuiSQfXEQ27fMNa9Wxyk62vD5RlRld0I=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>JTJcei7so2GAdQsv9FtOfDY7HSRZLDwj8Rc5Jt1dl4I9kvRdc3DC3AgWV8LcL5vzYyPsbjN3If56gg2YaFbahbOF/wxvyHn0LB28RZUhuH
.
.
+8hrh5ySlWl0ej5x0gh0doD537L1LqRZbzP0R++3BS5cqBAW8pmN1r5Tlwt0kTkHmafSOkBWvwvoZVQeDArnBLvHPtkT6Q9K2vT4QvrQjzh</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIEJzCCAo+gAwIBAgIUc33YkmOgONgZLiUdIcRsVPItWCUwDQYJKoZIhvcNAQELBQAwGjEYMBYG
A1UEAwwPaWRwMDEuamxmb28uY29tMB4XDTI1MDQwNjA2MjUxOFoXDTQ1MDQwNjA2MjUxOFowGjEY
.
.
.
W67RAmB9Kzs+onJfucXTYeLdTcv7sK8FPvxUWbsJj0bgXidpuhCXFUs=</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2p:Status>
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</saml2p:Status>
<saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_bdada20483d278656a675eb121a7b8ca"
IssueInstant="2025-04-09T13:58:19.437Z" Version="2.0">
<saml2:Issuer>https://idp01.xxxx.com/idp/shibboleth</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="
http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#_bdada20483d278656a675eb121a7b8ca">
<ds:Transforms>
<ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="
http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>asjKKk13hGvKDr6PdHdnhej/p+O1wvwJAfcK74QLsE8=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>hxBnvUgPMC2hl4b729SrvZgMDBUBIsJhYvUoF/9YiYQgKJplUieP0BjFJjnZkbrw5yw1fp0uhenTO8njZQp3ns3kWsNu992SowZWCsnHIsdZBNCAw/jQzzeq.
.
6I+IE6VG9pWez+B5GOr7fDciw8X1MzKdejQ1Y0Bq0PR//QOQV</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIEJzCCAo+gAwIBAgIUc33YkmOgONgZLiUdIcRsVPItWCUwDQYJKoZIhvcNAQELBQAwGjEYMBYG
A1UEAwwPaWRwMDEuamxmb28uY29tMB4XDTI1MDQwNjA2MjUxOFoXDTQ1MDQwNjA2MjUxOFowGjEY
.
.
.
FUE/+meDluNbZ1nImkA/lxDXS3/OLLkUveiJAcRhWxsNpHChdRtPVtaDqrqJYlsCpQ+WLw0H96tn
W67RAmB9Kzs+onJfucXTYeLdTcv7sK8FPvxUWbsJj0bgXidpuhCXFUs=</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2:Subject>
<saml2:NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="
https://idp01.xxxx.com/idp/shibboleth" SPNameQualifier="
https://zzzz.com:443/fed"
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">AAdzZWNyZXQxLCQnlD5Nbf9mkodP6zrNzVF502xO7lKRtSSsmKf5CHcGTGYT3x7F2h3uUZxQIeoigOyirgv9DQq6/b0DACc6E6JcRAaA+NX2eViJZ8O25ord14YhEoFIiDceWpaJsccotTL/jAzGp9lXbHtW7teD0oRWNZA/eiD/DUEXdH1cXP5edY1sZr++RoaxpSot4yX8hyktRALgC9rw0g==</saml2:NameID>
<saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<saml2:SubjectConfirmationData Address="100.36.177.53"
InResponseTo="id-IgJu6hZAQMJmcaOUKpIS7nGx2gY-"
NotOnOrAfter="2025-04-09T14:03:19.579Z" Recipient="
https://yyyy/fed/v1/sp/sso"/>
</saml2:SubjectConfirmation>
</saml2:Subject>
<saml2:Conditions NotBefore="2025-04-09T13:58:19.437Z"
NotOnOrAfter="2025-04-09T14:03:19.437Z">
<saml2:AudienceRestriction>
<saml2:Audience>https://aaaaa.com:443/fed</saml2:Audience>
</saml2:AudienceRestriction>
</saml2:Conditions>
<saml2:AuthnStatement AuthnInstant="2025-04-09T13:58:19.350Z"
SessionIndex="_dfa1ea475a6acd7db5d23318442445d8">
<saml2:SubjectLocality Address="100.36.177.53"/>
<saml2:AuthnContext>
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
</saml2:AuthnStatement>
<saml2:AttributeStatement>
<saml2:Attribute FriendlyName="schacHomeOrganization"
Name="urn:oid:1.3.6.1.4.1.25178.1.2.9"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml2:AttributeValue>xxxx.com</saml2:AttributeValue>
</saml2:Attribute>
</saml2:AttributeStatement>
</saml2:Assertion>
</saml2p:Response>
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
Virus-free.www.avast.com
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
<#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
On Wed, Apr 9, 2025 at 11:09 AM o haya <ohaya1001 at gmail.com> wrote:
> Hi Scott and Peter!!
>
> I really appreciate your responses/comments, especially Scott's comments
> about the attribute resolver... it is a LOT of information, especially
> conceptually, to digest for a newbie and the "glue" to the different pieces
> of information is the hardest part to try to understand. I mean I feel
> like I have a LOT of experience with federation, LDAPs, etc., but most of
> my work has been with COTS products, and some of the concepts in Shibboleth
> are still a little new to me, so it is taking a while for me.
>
> I think that I am kind of a "learn by doing" type person, so, personally,
> it is important in my learning process to get something, even something
> simple, working, and then I can go from there, so that is currently what I
> am trying to get to/achieve. Even if I can get just one of 2 attributes
> and mainly, the nameid part working, that would be a great starting point.
>
> As far as specifics, as mentioned, I am using OpenDJ (I tend to use OpenDJ
> in development, because it includes a control panel for administration,
> plus a standalone LDAP instance, in one package, but I have used Oracle
> OUD, AD, and even the old Oracle OID and the original SunDS, for years).
> OpenDJ includes a standard LDAP schema, similar to SunDS, I think, and
> currently I've configured the BEGINNING part of the Shib ldap properties:
>
>
>> ==================================================================================
>
> # LDAP authentication (and possibly attribute resolver) configuration
> # Note, this doesn't apply to the use of JAAS authentication via LDAP
>
> ## Authenticator strategy, either anonSearchAuthenticator,
> bindSearchAuthenticator, directAuthenticator, adAuthenticator
> idp.authn.LDAP.authenticator = anonSearchAuthenticator
>
> ## Connection properties ##
> idp.authn.LDAP.ldapURL = ldap://localhost:1389
> idp.authn.LDAP.useStartTLS = false
> # Time to wait for startTLS responses
> #idp.authn.LDAP.startTLSTimeout = PT3S
> # Time to wait for connections to open
> #idp.authn.LDAP.connectTimeout = PT3S
> # Time to wait for operation responses (e.g. search, bind)
> #idp.authn.LDAP.responseTimeout = PT3S
> # Connection strategy to use when multiple URLs are supplied, either
> ACTIVE_PASSIVE, ROUND_ROBIN, RANDOM
> #idp.authn.LDAP.connectionStrategy = ACTIVE_PASSIVE
>
> ## SSL configuration, either jvmTrust, certificateTrust, or keyStoreTrust
> #idp.authn.LDAP.sslConfig = certificateTrust
> ## If using certificateTrust above, set to the trusted certificate's path
> #idp.authn.LDAP.trustCertificates =
> %{idp.home}/credentials/ldap-server.crt
> ## If using keyStoreTrust above, set to the truststore path
> #idp.authn.LDAP.trustStore =
> %{idp.home}/credentials/ldap-server.truststore
>
> ## Return attributes during authentication
> # Setting this property will cause entry resolution to occur as part of
> authentication
> # Note that this property is not compatible with the adAuthenticator
> #idp.authn.LDAP.returnAttributes =
> passwordExpirationTime,loginGraceRemaining
>
> ## DN resolution properties ##
>
> # Search DN resolution, used by anonSearchAuthenticator,
> bindSearchAuthenticator
> # for AD: CN=Users,DC=example,DC=org
> idp.authn.LDAP.baseDN = ou=people,dc=xxxx,dc=com
> idp.authn.LDAP.subtreeSearch = true
> idp.authn.LDAP.userFilter = (cn={user})
> # bind search configuration
> # for AD: idp.authn.LDAP.bindDN=adminuser at domain.com
> idp.authn.LDAP.bindDN = cn=directory manager
>
> # Format DN resolution, used by directAuthenticator, adAuthenticator
> # for AD use idp.authn.LDAP.dnFormat=%s at domain.com
> idp.authn.LDAP.dnFormat =
> cn=%s,ou=people,dc=xxxx,dc=com
>
> ===========================================================================
>
>
>
> I have not changed anything in saml-nameid.xml or attribute-resolver.xml
> (I did make changes which caused the IdP to fail to start earlier, but I've
> since restored them to original).
>
> Jim
>
>
>
>
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> Virus-free.www.avast.com
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> <#m_-3722657078113250533_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
>
> On Wed, Apr 9, 2025 at 8:37 AM Cantor, Scott via users <
> users at shibboleth.net> wrote:
>
>> > I was seeing errors in the idp-warn.log about missing >
>> > certificat (.crt) files, even though I have TLS set to 'false' in
>> > the ldap.properties file.
>>
>> That's doesn't mean you're not applying other settings that assume they
>> exist.
>>
>> But using ldap:// instead of ldaps:// with the startTLS setting off
>> should not result in actual use of TLS in either of the two ways it gets
>> used. jvmTrust is probably a reasonable fallback option to set when not
>> using TLS at all since it shouldn't matter and doesn't require additional
>> setup.
>>
>> As for the documentation, I don't think the resolver material is
>> approachable, it doesn't explain any concepts. A section outlining what
>> it's really doing and how the connectors and definitions get applied is
>> needed.
>>
>> Having said which, the LDAP data connector topic should be all anybody
>> needs to set up a query, not to mention there's a specific example file in
>> the install for LDAP.
>>
>> But as for the NameID generation matetrial: that is as good as it's ever
>> going to get IMHO.
>>
>> -- Scott
>>
>>
>> --
>> For Consortium Member technical support, see
>> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250409/af0257cf/attachment.htm>
More information about the users
mailing list