<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle" type="text/css">P {margin-top:0;margin-bottom:0;}</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="direction: ltr;font-family: Book Antiqua;color: #000000;font-size: 12pt;">
Hi,<br>
<br>
We are trying to setup communication with a new service provider from our idp, their information was added to the relying-party.xml, attribute-filter.xml and we have obtained their metadata.<br>
<br>
After authentication with the new service provider we see that no attributes are released, the error message the admin of the service provider gave us is
<br>
<br>
<tt><font size="2">&gt; 2012-06-06 08:52:19 ERROR Shibboleth.AttributeResolver.Query [1959]: exception during SAML query to
</font></tt><a href="https://authfed.fiu.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery:" target="_blank"><tt><font size="2">https://authfed.fiu.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery:</font></tt></a><tt><font size="2"> CURLSOAPTransport failed while
 contacting SOAP endpoint (</font></tt><a href="https://authfed.fiu.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery" target="_blank"><tt><font size="2">https://authfed.fiu.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery</font></tt></a><tt><font size="2">): couldn't
 connect to host<br>
&gt; 2012-06-06 08:52:19 ERROR Shibboleth.AttributeResolver.Query [1959]: unable to obtain a SAML response from attribute authority</font></tt>
<br>
<br>
On our idp-process.log we see the following:<br>
<br>
14:36:17.672 - INFO [Shibboleth-Access:74] - 20120611T183617Z|74.122.104.103|authfed.fiu.edu:8443|/profile/SAML2/SOAP/AttributeQuery|<br>
14:36:17.810 - INFO [Shibboleth-Audit:989] - 20120611T183617Z|urn:oasis:names:tc:SAML:2.0:bindings:SOAP|_87853969cb3681e9897bf8a6da613477|https://corp.collegenet.com/shibboleth-sp/|urn:mace:shibboleth:2.0:profiles:saml2:query:attribute|https://authfed.fiu.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:SOAP|_363c828d29c131d01fa04d605feea6bd|jdoe011|||||<br>
<br>
<br>
<br>
We have opened up our firewall rules to the ips mentioned by the service provider but we still encounter this problem.&nbsp; We have previously configured other sp's with no problem.<br>
<br>
Has anybody else encountered this problem.&nbsp; If so any help would be much appreciated.<br>
<br>
Thanks!<br>
<br>
Here is our attribute-filter.xml file<br>
<br>
&lt;afp:AttributeFilterPolicy id=&quot;collegenetdev&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PolicyRequirementRule xsi:type=&quot;basic:AttributeRequesterString&quot; value=&quot;https://corp.collegenet.com/shibboleth-sp&quot;/&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule attributeID=&quot;uid&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeRule&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule attributeID=&quot;firstName&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeRule&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule attributeID=&quot;lastName&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeRule&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule attributeID=&quot;email&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeRule&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule attributeID=&quot;employeeType&quot;&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeRule&gt;<br>
&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeFilterPolicy&gt;<br>
<br>
<br>
<div><br>
<div><font face="Book Antiqua">___________________<br>
</font><font face="book antiqua">Juan Quintanilla</font></div>
<div><font face="book antiqua">305-348-6573</font></div>
<div><font face="book antiqua"><a href="mailto:jquin014@fiu.edu">jquin014@fiu.edu</a></font></div>
</div>
</div>
</body>
</html>