Shibboleth IdP is partially working with LDAP, but SAMLResponse NameID (and attributes) are missing

Peter Schober peter.schober at univie.ac.at
Wed Apr 9 18:54:30 UTC 2025


o haya via users <users at shibboleth.net> [2025-04-09 17:10 CEST]:
> currently I've configured the BEGINNING part of the Shib ldap properties:
[...]
> I have not changed anything in saml-nameid.xml or attribute-resolver.xml (I
> did make changes which caused the IdP to fail to start earlier, but I've
> since restored them to original).

o haya via users <users at shibboleth.net> [2025-04-09 17:31 CEST]:
> Here's what the SAMLResponse I am seeing looks like
[...]
>         <saml2:AttributeStatement>
>             <saml2:Attribute FriendlyName="schacHomeOrganization"
> Name="urn:oid:1.3.6.1.4.1.25178.1.2.9"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>                 <saml2:AttributeValue>xxxx.com</saml2:AttributeValue>
>             </saml2:Attribute>
>         </saml2:AttributeStatement>
>     </saml2:Assertion>
> </saml2p:Response>

I don't see any questions in those two emails?

If you're still asking "How do I get the example 'MyLDAP' Data
Connector working with a non-TLS capable LDAP DSA" you've probably
missed my previous reply pointing at the DataConnector's 'trustFile'
parameter which will prevent that, no matter what you're setting in
your ldap.properties.

HTH,
-peter


More information about the users mailing list