Thank you for the answer, and after authentication? Is there a way to get some more information about user&#39;s context? Maybe after login?<div><br></div><div>What do you think is the best way to modify shibboleth&#39;s behaviour based on user&#39;s context? Should I edit xml files or is there a way to call some kind of shibboleth&#39;s API?</div>
<div><br></div><div>Many thanks,</div><div>Marco<br><br><div class="gmail_quote">On 7 March 2012 10:39,  <span dir="ltr">&lt;<a href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Send users mailing list submissions to<br>
        <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
        <a href="http://shibboleth.net/mailman/listinfo/users" target="_blank">http://shibboleth.net/mailman/listinfo/users</a><br>
or, via email, send a message with subject or body &#39;help&#39; to<br>
        <a href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a><br>
<br>
You can reach the person managing the list at<br>
        <a href="mailto:users-owner@shibboleth.net">users-owner@shibboleth.net</a><br>
<br>
When replying, please edit your Subject line so it is more specific<br>
than &quot;Re: Contents of users digest...&quot;<br>
<br>
<br>
Today&#39;s Topics:<br>
<br>
   1. Re: Custom Remote User Handler (Chad La Joie)<br>
   2. Re: Custom Remote User Handler (Christopher Bland)<br>
   3. Re: Custom Remote User Handler (Chad La Joie)<br>
   4. Re: WAYF no longer linking correctly (Tom Scavo)<br>
   5. User&#39;s context (Marco Zanini)<br>
   6. Re: User&#39;s context (Chad La Joie)<br>
<br>
<br>
----------------------------------------------------------------------<br>
<br>
Message: 1<br>
Date: Tue, 6 Mar 2012 12:18:53 -0500<br>
From: Chad La Joie &lt;<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>&gt;<br>
Subject: Re: Custom Remote User Handler<br>
To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
Message-ID:<br>
        &lt;CACTY7uCEeZ2dU=<a href="mailto:tEx7aM3M4Kd2Q1Z-ODjSebM4U-S6Dv9d23OQ@mail.gmail.com">tEx7aM3M4Kd2Q1Z-ODjSebM4U-S6Dv9d23OQ@mail.gmail.com</a>&gt;<br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
Well, I think you&#39;re just confused about SAML in general.  The public<br>
interface to the IdP are the SAML endpoints that it exposes.  When the<br>
request that comes in is an authentication request then the IdP will<br>
try to authenticate a user via one of its configured authentication<br>
mechanisms.  This document talks about how the authentication<br>
mechanism is selected:<br>
<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn</a><br>
<br>
Why don&#39;t you start from the beginning and tell us what you&#39;re trying<br>
to accomplish instead of starting with question about specific<br>
configuration changes.  The answer may be &quot;you don&#39;t need to do<br>
anything special&quot;.<br>
<br>
<br>
On Tue, Mar 6, 2012 at 12:10, Christopher Bland &lt;<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>&gt; wrote:<br>
&gt;<br>
&gt; Chad,<br>
&gt;<br>
&gt; Now I&#39;m confused.? In our current implementation we are using a SAML<br>
&gt; profile (<a href="https://idp.fdu.edu/idp/profile/SAML2/Redirect/SSO" target="_blank">https://idp.fdu.edu/idp/profile/SAML2/Redirect/SSO</a>) but I do not<br>
&gt; believe there is a remote user profile or at least I didn&#39;t get that from my<br>
&gt; reading on setting remote user up.? Clearly I need to expand my<br>
&gt; understanding of this.? I think I am missing the link between login handlers<br>
&gt; and profiles.<br>
&gt;<br>
&gt; Any suggested docs?<br>
&gt;<br>
&gt; -Chris<br>
&gt;<br>
&gt;<br>
&gt; On 3/6/12 11:57 AM, Chad La Joie wrote:<br>
&gt;<br>
&gt; No, you can not directly target URLs used by the authentication engine.<br>
&gt;<br>
&gt; On Tue, Mar 6, 2012 at 11:54, Christopher Bland &lt;<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>&gt; wrote:<br>
&gt;<br>
&gt; Based on my reading and understanding I should be able to specify<br>
&gt; <a href="https://idp.fdu.edu/idp/Authn/GoogleApps" target="_blank">https://idp.fdu.edu/idp/Authn/GoogleApps</a> as my &quot; Sign-in page URL&quot;.<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; Chad La Joie<br>
&gt; <a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
&gt; trusted identities, delivered<br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to<br>
&gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; Christopher Bland<br>
&gt; Systems Manager<br>
&gt; Information Systems and Technology<br>
&gt; 1000 River Road, Teaneck NJ 07666<br>
&gt; Mail Stop: T-BH1-01<br>
&gt; : <a href="tel:201-692-2414" value="+12016922414">201-692-2414</a> | : <a href="tel:201-692-2494" value="+12016922494">201-692-2494</a> | : <a href="mailto:chris@fdu.edu">chris@fdu.edu</a><br>
&gt; &quot;Fairleigh Dickinson University will never<br>
&gt; ?????????????????????????????????ask for your password. Please do not<br>
&gt; share it with others!&quot;<br>
&gt;<br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to<br>
&gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
<br>
--<br>
Chad La Joie<br>
<a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
trusted identities, delivered<br>
<br>
<br>
------------------------------<br>
<br>
Message: 2<br>
Date: Tue, 06 Mar 2012 13:24:18 -0500<br>
From: Christopher Bland &lt;<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>&gt;<br>
Subject: Re: Custom Remote User Handler<br>
To: <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
Message-ID: &lt;<a href="mailto:4F565652.6050902@fdu.edu">4F565652.6050902@fdu.edu</a>&gt;<br>
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br>
<br>
Chad,<br>
<br>
Thanks for the link to IdpUserAuthn doc.  I had read it before dealing<br>
with another issue but totally missed my current need to specify the<br>
authentication method in Google&#39;s custom relying party tag. Do you think<br>
that the following changes will work:<br>
<br>
relying-party.xml<br>
&lt;RelyingParty id=&quot;<a href="http://google.com" target="_blank">google.com</a>&quot;<br>
             provider=&quot;<a href="https://idp.fdu.edu/idp/shibboleth" target="_blank">https://idp.fdu.edu/idp/shibboleth</a>&quot;<br>
defaultAuthenticationMethod=&quot;??????? not sure of appropriate class for<br>
remote user ???????&quot;<br>
             defaultSigningCredentialRef=&quot;IdPCredential&quot;&gt;<br>
&lt;ProfileConfiguration xsi:type=&quot;saml:SAML2SSOProfile&quot;<br>
encryptAssertions=&quot;never&quot; encryptNameIds=&quot;never&quot; /&gt;<br>
&lt;/RelyingParty&gt;<br>
<br>
handler.xml<br>
&lt;ph:LoginHandler xsi:type=&quot;ph:RemoteUser&quot;&gt;<br>
&lt;ph:protectedServletPath=&quot;/idp/Authn/GoogleApps&quot;&gt;<br>
&lt;ph:AuthenticationMethod&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:?????????&lt;/ph:AuthenticationMethod&gt;<br>
(don&#39;t want to use unspecified because then it becomes default)<br>
&lt;/ph:LoginHandler&gt;<br>
<br>
web.xml<br>
&lt;servlet&gt;<br>
&lt;servlet-name&gt;GoogleAppsAuthHandler&lt;/servlet-name&gt;<br>
&lt;servlet-class&gt;edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserAuthServlet&lt;/servlet-class&gt;<br>
&lt;load-on-startup&gt;5&lt;/load-on-startup&gt;<br>
&lt;/servlet&gt;<br>
<br>
&lt;servlet-mapping&gt;<br>
&lt;servlet-name&gt;GoogleAppsAuthHandler&lt;/servlet-name&gt;<br>
&lt;url-pattern&gt;/Authn/GoogleApps&lt;/url-pattern&gt;<br>
&lt;/servlet-mapping&gt;<br>
<br>
http.conf<br>
&lt;Location /idp/Authn/GoogleApps&gt;<br>
           AuthType Basic AuthName &quot;Identity Provider Authentication&quot;<br>
           AuthUserFile /PATH/TO/USER/FILE<br>
           require valid-user<br>
&lt;/Location&gt;<br>
<br>
<br>
-Chris<br>
<br>
On 3/6/12 12:18 PM, Chad La Joie wrote:<br>
&gt; Well, I think you&#39;re just confused about SAML in general.  The public<br>
&gt; interface to the IdP are the SAML endpoints that it exposes.  When the<br>
&gt; request that comes in is an authentication request then the IdP will<br>
&gt; try to authenticate a user via one of its configured authentication<br>
&gt; mechanisms.  This document talks about how the authentication<br>
&gt; mechanism is selected:<br>
&gt; <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn</a><br>
<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <a href="http://shibboleth.net/pipermail/users/attachments/20120306/c829c6e8/attachment-0001.html" target="_blank">http://shibboleth.net/pipermail/users/attachments/20120306/c829c6e8/attachment-0001.html</a><br>
<br>
------------------------------<br>
<br>
Message: 3<br>
Date: Tue, 6 Mar 2012 13:31:37 -0500<br>
From: Chad La Joie &lt;<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>&gt;<br>
Subject: Re: Custom Remote User Handler<br>
To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
Message-ID:<br>
        &lt;<a href="mailto:CACTY7uAGqzWcgW%2B8EcOmMK0GtbNjUQ0AN901gbKdwZtAKFyuwQ@mail.gmail.com">CACTY7uAGqzWcgW+8EcOmMK0GtbNjUQ0AN901gbKdwZtAKFyuwQ@mail.gmail.com</a>&gt;<br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
You will need to pick a URI for your custom method.  You can *not* use<br>
the urn:oasis:names:tc:SAML namespace as that&#39;s controlled by the SAML<br>
committee.  But it&#39;s just a URI so pick a URL you control.<br>
<br>
On Tue, Mar 6, 2012 at 13:24, Christopher Bland &lt;<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>&gt; wrote:<br>
&gt; Chad,<br>
&gt;<br>
&gt; Thanks for the link to IdpUserAuthn doc.? I had read it before dealing with<br>
&gt; another issue but totally missed my current need to specify the<br>
&gt; authentication method in Google&#39;s custom relying party tag. Do you think<br>
&gt; that the following changes will work:<br>
&gt;<br>
&gt; relying-party.xml<br>
&gt; ??? &lt;RelyingParty id=&quot;<a href="http://google.com" target="_blank">google.com</a>&quot;<br>
&gt; ??????????? provider=&quot;<a href="https://idp.fdu.edu/idp/shibboleth" target="_blank">https://idp.fdu.edu/idp/shibboleth</a>&quot;<br>
&gt; ??????????? defaultAuthenticationMethod=&quot;??????? not sure of appropriate<br>
&gt; class for remote user ???????&quot;<br>
&gt; ??????????? defaultSigningCredentialRef=&quot;IdPCredential&quot;&gt;<br>
&gt; ??????? &lt;ProfileConfiguration xsi:type=&quot;saml:SAML2SSOProfile&quot;<br>
&gt; encryptAssertions=&quot;never&quot; encryptNameIds=&quot;never&quot; /&gt;<br>
&gt; ??? &lt;/RelyingParty&gt;<br>
&gt;<br>
&gt; handler.xml<br>
&gt; ??? &lt;ph:LoginHandler xsi:type=&quot;ph:RemoteUser&quot;&gt;<br>
&gt; ??????? &lt;ph:protectedServletPath=&quot;/idp/Authn/GoogleApps&quot;&gt;<br>
&gt;<br>
&gt; &lt;ph:AuthenticationMethod&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:?????????&lt;/ph:AuthenticationMethod&gt;<br>
&gt; (don&#39;t want to use unspecified because then it becomes default)<br>
&gt; ??? &lt;/ph:LoginHandler&gt;<br>
&gt;<br>
&gt; web.xml<br>
&gt; ??? &lt;servlet&gt;<br>
&gt; ??????? &lt;servlet-name&gt;GoogleAppsAuthHandler&lt;/servlet-name&gt;<br>
&gt;<br>
&gt; &lt;servlet-class&gt;edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserAuthServlet&lt;/servlet-class&gt;<br>
&gt; ??????? &lt;load-on-startup&gt;5&lt;/load-on-startup&gt;<br>
&gt; ??? &lt;/servlet&gt;<br>
&gt;<br>
&gt; ??? &lt;servlet-mapping&gt;<br>
&gt; ??????? &lt;servlet-name&gt;GoogleAppsAuthHandler&lt;/servlet-name&gt;<br>
&gt; ??????? &lt;url-pattern&gt;/Authn/GoogleApps&lt;/url-pattern&gt;<br>
&gt; ??? &lt;/servlet-mapping&gt;<br>
&gt;<br>
&gt; http.conf<br>
&gt; ??? &lt;Location /idp/Authn/GoogleApps&gt;<br>
&gt; ????????? AuthType Basic AuthName &quot;Identity Provider Authentication&quot;<br>
&gt; ????????? AuthUserFile /PATH/TO/USER/FILE<br>
&gt; ????????? require valid-user<br>
&gt; ??? &lt;/Location&gt;<br>
&gt;<br>
&gt;<br>
&gt; -Chris<br>
&gt;<br>
&gt;<br>
&gt; On 3/6/12 12:18 PM, Chad La Joie wrote:<br>
&gt;<br>
&gt; Well, I think you&#39;re just confused about SAML in general.  The public<br>
&gt; interface to the IdP are the SAML endpoints that it exposes.  When the<br>
&gt; request that comes in is an authentication request then the IdP will<br>
&gt; try to authenticate a user via one of its configured authentication<br>
&gt; mechanisms.  This document talks about how the authentication<br>
&gt; mechanism is selected:<br>
&gt; <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn</a><br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to<br>
&gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
--<br>
Chad La Joie<br>
<a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
trusted identities, delivered<br>
<br>
<br>
------------------------------<br>
<br>
Message: 4<br>
Date: Tue, 6 Mar 2012 19:14:45 -0500<br>
From: Tom Scavo &lt;<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>&gt;<br>
Subject: Re: WAYF no longer linking correctly<br>
To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
Message-ID:<br>
        &lt;CAEtu=dNP-oebbRYF5MtGSAcT=<a href="mailto:JL59U1u1KYeW10uBQpVJP4aCg@mail.gmail.com">JL59U1u1KYeW10uBQpVJP4aCg@mail.gmail.com</a>&gt;<br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
On Tue, Mar 6, 2012 at 10:41 AM, Chad La Joie &lt;<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>&gt; wrote:<br>
&gt; And does that error occur if you run a recent version of the DS?<br>
&gt; 1.1.3 is the latest.<br>
<br>
Rod should be able to answer that question immediately. In any case,<br>
InCommon has received multiple such reports of errors, so we will<br>
remove the embedded double quotes from InCommon metadata ASAP. That<br>
means tomorrow&#39;s signed metadata aggregate will not contain embedded<br>
double quotes.<br>
<br>
Tom Scavo<br>
Operations Manager<br>
InCommon.org<br>
<br>
&gt; On Tue, Mar 6, 2012 at 10:19, Tom Scavo &lt;<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>&gt; wrote:<br>
&gt;&gt; On Tue, Mar 6, 2012 at 10:05 AM, Gabriel Jimenez &lt;<a href="mailto:Gabe.Jimenez@nau.edu">Gabe.Jimenez@nau.edu</a>&gt; wrote:<br>
&gt;&gt;&gt;<br>
&gt;&gt;&gt; We are using shibboleth-discovery-service-1.1.0.<br>
&gt;&gt;<br>
&gt;&gt; Then I believe this is a bug and you should file an issue in Shibboleth jira.<br>
&gt;&gt;<br>
&gt;&gt; Tom<br>
&gt;&gt; --<br>
&gt;&gt; To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; Chad La Joie<br>
&gt; <a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
&gt; trusted identities, delivered<br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
------------------------------<br>
<br>
Message: 5<br>
Date: Wed, 7 Mar 2012 10:06:53 +0000<br>
From: Marco Zanini &lt;<a href="mailto:marco.zanini@lero.ie">marco.zanini@lero.ie</a>&gt;<br>
Subject: User&#39;s context<br>
To: <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
Message-ID:<br>
        &lt;CAG1Po3t9SAOZGBCWJNgs7STRd9RQ644c=<a href="mailto:bOqn65LAoTX4oE9Cg@mail.gmail.com">bOqn65LAoTX4oE9Cg@mail.gmail.com</a>&gt;<br>
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br>
<br>
Hi to all,<br>
I am about to develop an application to apply different countermeasures<br>
depending on the user&#39;s context. I would like for example the user to use<br>
different types of login (username/password, two-step authentication) based<br>
on the context. I was thinking of developing an external authentication<br>
component for shibboleth.<br>
*What are the information about user&#39;s context that I can get from<br>
shibboleth when it calls my login handler?*<br>
I am using Google Apps as my service provider.<br>
<br>
Thank you,<br>
Marco<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <a href="http://shibboleth.net/pipermail/users/attachments/20120307/e7ab50ca/attachment-0001.html" target="_blank">http://shibboleth.net/pipermail/users/attachments/20120307/e7ab50ca/attachment-0001.html</a><br>
<br>
------------------------------<br>
<br>
Message: 6<br>
Date: Wed, 7 Mar 2012 05:39:21 -0500<br>
From: Chad La Joie &lt;<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>&gt;<br>
Subject: Re: User&#39;s context<br>
To: Shib Users &lt;<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br>
Message-ID:<br>
        &lt;<a href="mailto:CACTY7uBeDCTOfddsrZJv_pgdxW_M6P-5ZhT66Xs4UZib-sui8Q@mail.gmail.com">CACTY7uBeDCTOfddsrZJv_pgdxW_M6P-5ZhT66Xs4UZib-sui8Q@mail.gmail.com</a>&gt;<br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
Well, prior to authentication the only thing you know is the protocol<br>
in use (SAML 1 or 2), the SP requesting the authentication, and if it<br>
requested a specific method.  All of that is available in the<br>
LoginContext object available to the login handler.<br>
<br>
On Wed, Mar 7, 2012 at 05:06, Marco Zanini &lt;<a href="mailto:marco.zanini@lero.ie">marco.zanini@lero.ie</a>&gt; wrote:<br>
&gt; Hi to all,<br>
&gt; I am about to develop an application to apply different countermeasures<br>
&gt; depending on the user&#39;s context. I would like for example the user to use<br>
&gt; different types of login (username/password, two-step authentication) based<br>
&gt; on the context. I was thinking of developing an external authentication<br>
&gt; component for shibboleth.<br>
&gt; What are the information about user&#39;s context that I can get from shibboleth<br>
&gt; when it calls my login handler?<br>
&gt; I am using Google Apps as my service provider.<br>
&gt;<br>
&gt; Thank you,<br>
&gt; Marco<br>
&gt;<br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to<br>
&gt; <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
--<br>
Chad La Joie<br>
<a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
trusted identities, delivered<br>
<br>
<br>
------------------------------<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
End of users Digest, Vol 9, Issue 19<br>
************************************<br>
</blockquote></div><br></div>