Shibboleth IdP is partially working with LDAP, but SAMLResponse NameID (and attributes) are missing

o haya ohaya1001 at gmail.com
Wed Apr 9 15:31:11 UTC 2025


Hi,

Here's what the SAMLResponse I am seeing looks like (sorry for the
obfuscations):

<?xml version="1.0" encoding="UTF-8"?><saml2p:Response
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="
https://yyy/fed/v1/sp/sso" ID="_d14919a3c5d9e2cc8455440f4f7443a6"
InResponseTo="id-IgJu6hZAQMJmcaOUKpIS7nGx2gY-"
IssueInstant="2025-04-09T13:58:19.437Z" Version="2.0">
    <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">
https://idp01.xxxx.com/idp/shibboleth</saml2:Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
            <ds:SignatureMethod Algorithm="
http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
            <ds:Reference URI="#_d14919a3c5d9e2cc8455440f4f7443a6">
                <ds:Transforms>
                    <ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                    <ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
                </ds:Transforms>
                <ds:DigestMethod Algorithm="
http://www.w3.org/2001/04/xmlenc#sha256"/>

<ds:DigestValue>TPt9U+iX0uSYuiSQfXEQ27fMNa9Wxyk62vD5RlRld0I=</ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>

<ds:SignatureValue>JTJcei7so2GAdQsv9FtOfDY7HSRZLDwj8Rc5Jt1dl4I9kvRdc3DC3AgWV8LcL5vzYyPsbjN3If56gg2YaFbahbOF/wxvyHn0LB28RZUhuH
.
.
+8hrh5ySlWl0ej5x0gh0doD537L1LqRZbzP0R++3BS5cqBAW8pmN1r5Tlwt0kTkHmafSOkBWvwvoZVQeDArnBLvHPtkT6Q9K2vT4QvrQjzh</ds:SignatureValue>
        <ds:KeyInfo>
            <ds:X509Data>

<ds:X509Certificate>MIIEJzCCAo+gAwIBAgIUc33YkmOgONgZLiUdIcRsVPItWCUwDQYJKoZIhvcNAQELBQAwGjEYMBYG
A1UEAwwPaWRwMDEuamxmb28uY29tMB4XDTI1MDQwNjA2MjUxOFoXDTQ1MDQwNjA2MjUxOFowGjEY
.
.
.
W67RAmB9Kzs+onJfucXTYeLdTcv7sK8FPvxUWbsJj0bgXidpuhCXFUs=</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml2p:Status>
        <saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
    </saml2p:Status>
    <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_bdada20483d278656a675eb121a7b8ca"
IssueInstant="2025-04-09T13:58:19.437Z" Version="2.0">
        <saml2:Issuer>https://idp01.xxxx.com/idp/shibboleth</saml2:Issuer>
        <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
            <ds:SignedInfo>
                <ds:CanonicalizationMethod Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
                <ds:SignatureMethod Algorithm="
http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
                <ds:Reference URI="#_bdada20483d278656a675eb121a7b8ca">
                    <ds:Transforms>
                        <ds:Transform Algorithm="
http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                        <ds:Transform Algorithm="
http://www.w3.org/2001/10/xml-exc-c14n#"/>
                    </ds:Transforms>
                    <ds:DigestMethod Algorithm="
http://www.w3.org/2001/04/xmlenc#sha256"/>

<ds:DigestValue>asjKKk13hGvKDr6PdHdnhej/p+O1wvwJAfcK74QLsE8=</ds:DigestValue>
                </ds:Reference>
            </ds:SignedInfo>

<ds:SignatureValue>hxBnvUgPMC2hl4b729SrvZgMDBUBIsJhYvUoF/9YiYQgKJplUieP0BjFJjnZkbrw5yw1fp0uhenTO8njZQp3ns3kWsNu992SowZWCsnHIsdZBNCAw/jQzzeq.
.
6I+IE6VG9pWez+B5GOr7fDciw8X1MzKdejQ1Y0Bq0PR//QOQV</ds:SignatureValue>
            <ds:KeyInfo>
                <ds:X509Data>

<ds:X509Certificate>MIIEJzCCAo+gAwIBAgIUc33YkmOgONgZLiUdIcRsVPItWCUwDQYJKoZIhvcNAQELBQAwGjEYMBYG
A1UEAwwPaWRwMDEuamxmb28uY29tMB4XDTI1MDQwNjA2MjUxOFoXDTQ1MDQwNjA2MjUxOFowGjEY
.
.
.
FUE/+meDluNbZ1nImkA/lxDXS3/OLLkUveiJAcRhWxsNpHChdRtPVtaDqrqJYlsCpQ+WLw0H96tn
W67RAmB9Kzs+onJfucXTYeLdTcv7sK8FPvxUWbsJj0bgXidpuhCXFUs=</ds:X509Certificate>
                </ds:X509Data>
            </ds:KeyInfo>
        </ds:Signature>
        <saml2:Subject>
            <saml2:NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="
https://idp01.xxxx.com/idp/shibboleth" SPNameQualifier="
https://zzzz.com:443/fed"
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">AAdzZWNyZXQxLCQnlD5Nbf9mkodP6zrNzVF502xO7lKRtSSsmKf5CHcGTGYT3x7F2h3uUZxQIeoigOyirgv9DQq6/b0DACc6E6JcRAaA+NX2eViJZ8O25ord14YhEoFIiDceWpaJsccotTL/jAzGp9lXbHtW7teD0oRWNZA/eiD/DUEXdH1cXP5edY1sZr++RoaxpSot4yX8hyktRALgC9rw0g==</saml2:NameID>
            <saml2:SubjectConfirmation
Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                <saml2:SubjectConfirmationData Address="100.36.177.53"
InResponseTo="id-IgJu6hZAQMJmcaOUKpIS7nGx2gY-"
NotOnOrAfter="2025-04-09T14:03:19.579Z" Recipient="
https://yyyy/fed/v1/sp/sso"/>
            </saml2:SubjectConfirmation>
        </saml2:Subject>
        <saml2:Conditions NotBefore="2025-04-09T13:58:19.437Z"
NotOnOrAfter="2025-04-09T14:03:19.437Z">
            <saml2:AudienceRestriction>
                <saml2:Audience>https://aaaaa.com:443/fed</saml2:Audience>
            </saml2:AudienceRestriction>
        </saml2:Conditions>
        <saml2:AuthnStatement AuthnInstant="2025-04-09T13:58:19.350Z"
SessionIndex="_dfa1ea475a6acd7db5d23318442445d8">
            <saml2:SubjectLocality Address="100.36.177.53"/>
            <saml2:AuthnContext>

<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
            </saml2:AuthnContext>
        </saml2:AuthnStatement>
        <saml2:AttributeStatement>
            <saml2:Attribute FriendlyName="schacHomeOrganization"
Name="urn:oid:1.3.6.1.4.1.25178.1.2.9"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                <saml2:AttributeValue>xxxx.com</saml2:AttributeValue>
            </saml2:Attribute>
        </saml2:AttributeStatement>
    </saml2:Assertion>
</saml2p:Response>





<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
Virus-free.www.avast.com
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
<#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>

On Wed, Apr 9, 2025 at 11:09 AM o haya <ohaya1001 at gmail.com> wrote:

> Hi Scott and Peter!!
>
> I really appreciate your responses/comments, especially Scott's comments
> about the attribute resolver... it is a LOT of information, especially
> conceptually, to digest for a newbie and the "glue" to the different pieces
> of information is the hardest part to try to understand.  I mean I feel
> like I have a LOT of experience with federation, LDAPs, etc., but most of
> my work has been with COTS products, and some of the concepts in Shibboleth
> are still a little new to me, so it is taking a while for me.
>
> I think that I am kind of a "learn by doing" type person, so, personally,
> it is important in my learning process to get something, even something
> simple, working, and then I can go from there, so that is currently what I
> am trying to get to/achieve.  Even if I can get just one of 2 attributes
> and mainly, the nameid part working, that would be a great starting point.
>
> As far as specifics, as mentioned, I am using OpenDJ (I tend to use OpenDJ
> in development, because it includes a control panel for administration,
> plus a standalone LDAP instance, in one package, but I have used Oracle
> OUD, AD, and even the old Oracle OID and the original SunDS, for years).
> OpenDJ includes a standard LDAP schema, similar to SunDS, I think, and
> currently I've configured the BEGINNING part of the Shib ldap properties:
>
>
>> ==================================================================================
>
> # LDAP authentication (and possibly attribute resolver) configuration
> # Note, this doesn't apply to the use of JAAS authentication via LDAP
>
> ## Authenticator strategy, either anonSearchAuthenticator,
> bindSearchAuthenticator, directAuthenticator, adAuthenticator
> idp.authn.LDAP.authenticator                   = anonSearchAuthenticator
>
> ## Connection properties ##
> idp.authn.LDAP.ldapURL                          = ldap://localhost:1389
> idp.authn.LDAP.useStartTLS                     = false
> # Time to wait for startTLS responses
> #idp.authn.LDAP.startTLSTimeout                 = PT3S
> # Time to wait for connections to open
> #idp.authn.LDAP.connectTimeout                  = PT3S
> # Time to wait for operation responses (e.g. search, bind)
> #idp.authn.LDAP.responseTimeout                 = PT3S
> # Connection strategy to use when multiple URLs are supplied, either
> ACTIVE_PASSIVE, ROUND_ROBIN, RANDOM
> #idp.authn.LDAP.connectionStrategy               = ACTIVE_PASSIVE
>
> ## SSL configuration, either jvmTrust, certificateTrust, or keyStoreTrust
> #idp.authn.LDAP.sslConfig                       = certificateTrust
> ## If using certificateTrust above, set to the trusted certificate's path
> #idp.authn.LDAP.trustCertificates                =
> %{idp.home}/credentials/ldap-server.crt
> ## If using keyStoreTrust above, set to the truststore path
> #idp.authn.LDAP.trustStore                       =
> %{idp.home}/credentials/ldap-server.truststore
>
> ## Return attributes during authentication
> # Setting this property will cause entry resolution to occur as part of
> authentication
> # Note that this property is not compatible with the adAuthenticator
> #idp.authn.LDAP.returnAttributes                 =
> passwordExpirationTime,loginGraceRemaining
>
> ## DN resolution properties ##
>
> # Search DN resolution, used by anonSearchAuthenticator,
> bindSearchAuthenticator
> # for AD: CN=Users,DC=example,DC=org
> idp.authn.LDAP.baseDN                           = ou=people,dc=xxxx,dc=com
> idp.authn.LDAP.subtreeSearch                   = true
> idp.authn.LDAP.userFilter                       = (cn={user})
> # bind search configuration
> # for AD: idp.authn.LDAP.bindDN=adminuser at domain.com
> idp.authn.LDAP.bindDN                           = cn=directory manager
>
> # Format DN resolution, used by directAuthenticator, adAuthenticator
> # for AD use idp.authn.LDAP.dnFormat=%s at domain.com
> idp.authn.LDAP.dnFormat                         =
> cn=%s,ou=people,dc=xxxx,dc=com
>
> ===========================================================================
>
>
>
> I have not changed anything in saml-nameid.xml or attribute-resolver.xml
> (I did make changes which caused the IdP to fail to start earlier, but I've
> since restored them to original).
>
> Jim
>
>
>
>
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> Virus-free.www.avast.com
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> <#m_-3722657078113250533_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
>
> On Wed, Apr 9, 2025 at 8:37 AM Cantor, Scott via users <
> users at shibboleth.net> wrote:
>
>> > I was seeing errors in the idp-warn.log about missing >
>> > certificat  (.crt) files, even though I have TLS set to 'false' in
>> > the ldap.properties file.
>>
>> That's doesn't mean you're not applying other settings that assume they
>> exist.
>>
>> But using ldap:// instead of ldaps:// with the startTLS setting off
>> should not result in actual use of TLS in either of the two ways it gets
>> used. jvmTrust is probably a reasonable fallback option to set when not
>> using TLS at all since it shouldn't matter and doesn't require additional
>> setup.
>>
>> As for the documentation, I don't think the resolver material is
>> approachable, it doesn't explain any concepts. A section outlining what
>> it's really doing and how the connectors and definitions get applied is
>> needed.
>>
>> Having said which, the LDAP data connector topic should be all anybody
>> needs to set up a query, not to mention there's a specific example file in
>> the install for LDAP.
>>
>> But as for the NameID generation matetrial: that is as good as it's ever
>> going to get IMHO.
>>
>> -- Scott
>>
>>
>> --
>> For Consortium Member technical support, see
>> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250409/af0257cf/attachment.htm>


More information about the users mailing list