OIDC Claim Release Problems

Bryan K. Walton bwalton.25245 at leepfrog.com
Tue Sep 2 19:22:48 UTC 2025


Thank you Emilio!

This was indeed my problem. Thank you a 1000 times!

-Bryan

On Tue, Sep 02, 2025 at 03:11:32PM -0400, Emilio Recio via users wrote:
> I think something similar happened to me. It had something to do with the
> attribute encoder... Not sure if you're running into the same issue, but
> you might want to check. Basically we had our shib over years and years and
> still using somewhat old/modded XML files. From my comments...
> 
> Warning in order to make this work, you have to add an
>              attribute encoder to the "original" SAML attribute. When they
> created
>              it, they overrode it as SAML only. This is true of all
> attributes
>              with the AttributeEncoder tag for SAML. Perhaps a few below
> too, in
>              the profile scope. (See conf/attribute-resolver.xml id="email"
> ...
>     <AttributeDefinition id="email" xsi:type="Simple">
>         <InputDataConnector ref="udldap" attributeNames="mail"/>
>         <AttributeEncoder xsi:type="SAML1String"
> name="urn:mace:dir:attribute-def:mail" encodeType="false" />
>         <AttributeEncoder xsi:type="SAML2String"
> name="urn:oid:0.9.2342.19200300.100.1.3" friendlyName="mail" />
>         <!-- See Note in oidc-attribute-filter.xml -->
> *        <AttributeEncoder xsi:type="oidc:OIDCString" name="email" />*
> 
> Thanks,
> Emilio
> 
> 
> 
> On Tue, Sep 2, 2025 at 2:47 PM Bryan K. Walton via users <
> users at shibboleth.net> wrote:
> 
> > We have a working Shibboleth IdP that has been doing SAML for many
> > years.  We are trying to add OIDC/Oauth to this server.  I've followed
> > the instructions found here:
> >
> >
> > https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP
> >
> > I've setup a temporary OIDC application on my workstation that uses
> > mod_auth_openidc.
> >
> > Authentication appears to be working to the mod_auth_openidc protected
> > web page.  Our Shibboleth IdP is releasing a pairwise version of the
> > required subject claim and I see that in my application's Apache logs
> > as the remote user.
> >
> > However, I'm trying and failing to get my remote user changed to
> > email.  I've set my mod_auth_openidc config to use email for
> > "OIDCRemoteUserClaim".  I also have OIDCScope set to:
> > "openid email profile".
> >
> > Now, when I login to the proteced application, I
> > get:
> >
> > [Tue Sep 02 13:38:10.399527 2025] [auth_openidc:warn] [pid 1870717:tid
> > 1870717] [client 10.1.88.51:39498] oidc_get_remote_user: JSON object did
> > not contain a "email" string
> > [Tue Sep 02 13:38:10.399634 2025]
> > [auth_openidc:error] [pid 1870717:tid 1870717] [client 10.1.88.51:39498]
> > oidc_response_set_request_user: OIDCRemoteUserClaim is set to "email",
> > but could not set the remote user based on the requested claim "email"
> > and the available claims for the user
> > [Tue Sep 02 13:38:10.399662 2025] [auth_openidc:error] [pid 1870717:tid
> > 1870717] [client 10.1.88.51:39498] oidc_response_process: remote user
> > could not be set
> >
> > In my IdP's attribute-filter.xml, I have the following:
> >
> > <AttributeFilterPolicy id="OPENID_SCOPE_EMAIL">
> >         <PolicyRequirementRule xsi:type="oidc:OIDCScope" value="email" />
> >         <AttributeRule attributeID="mail">
> >                 <PermitValueRule xsi:type="ANY" />
> >         </AttributeRule>
> >         <AttributeRule attributeID="email_verified">
> >                 <PermitValueRule xsi:type="ANY" />
> >         </AttributeRule>
> > </AttributeFilterPolicy>
> >
> > One more thing that I will add.  We have no difficulty release the email
> > attribute to SAML applications.
> >
> > If anybody can point me to where I might have gone astray, I would
> > appreciate it.
> >
> > Thanks,
> > Bryan
> >
> > --
> > Bryan K. Walton                                           319-337-3877
> > Senior Linux Systems Administrator          Leepfrog Technologies, Inc
> > --
> > For Consortium Member technical support, see
> > https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> > To unsubscribe from this list send an email to
> > users-unsubscribe at shibboleth.net
> >

> -- 
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


-- 
Bryan K. Walton						  319-337-3877 
Senior Linux Systems Administrator	    Leepfrog Technologies, Inc 


More information about the users mailing list