Hi Yannick,<div><br></div><div>Thank you for the reply.  I have shibd.logger set to be DEBUG already, is there a way to increase the logging even further?</div><div><br></div><div>Since you have done this before, did you have to do anything with the attribure mapping to force decryption?</div>
<div><br></div><div>Thanks</div><div><br></div><div>Rob<br><br><div class="gmail_quote">On Fri, Jul 20, 2012 at 1:36 PM, Yannick Béot <span dir="ltr">&lt;<a href="mailto:yannick.beot@gmail.com" target="_blank">yannick.beot@gmail.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Perhaps, you should rise the debug level in the shibd.logger file:<div><div><br></div><div>At some point, you should have the attributestatement decrypted</div>
<div><br></div><div>I have tested with an encrypted assertion and in the logs I get:</div>
<div>2012-07-10 06:50:31 DEBUG Shibboleth.SSO.SAML2 [16]: decrypted Assertion: &lt;Assertion xmlns=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot; ID=&quot;_e7ce8557-1069-4684-bfc9-36db796f8d21&quot; IssueInstant=&quot;2012-07-10T04:50:29.711Z&quot; Version=&quot;2.0&quot;&gt;&lt;Issuer&gt;<a href="http://adfsxv.erp2.manitowoc.com/adfs/services/trust" target="_blank">http://adfsxv.erp2.manitowoc.com/adfs/services/trust</a>&lt;/Issuer&gt;&lt;ds:Signature xmlns:ds=&quot;<a href="http://www.w3.org/2000/09/xmldsig#" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;&lt;ds:SignedInfo&gt;&lt;ds:CanonicalizationMethod Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#" target="_blank">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;/&gt;&lt;ds:SignatureMeth...</div>
<div><div class="h5">
<div><br></div><div><br></div><div class="gmail_quote">On Fri, Jul 20, 2012 at 7:32 PM, Rob Whitener <span dir="ltr">&lt;<a href="mailto:rob.whitener@audaxhealth.com" target="_blank">rob.whitener@audaxhealth.com</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Thanks for getting back to me.  The saml prefix is indeed defined based on the smal2 namespace.  Also, I did see in the logs what looks like the encrypted attributes getting unpacked:<div>

<br></div><div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject.Builder [1]: located XMLObjectBuilder for element name: saml:EncryptedAttribute</div>
<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child element (saml:EncryptedAttribute)</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling DOM element (saml:EncryptedAttribute)</div>


<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child nodes of DOM element (saml:EncryptedAttribute)</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject.Builder [1]: located XMLObjectBuilder for element name: {<a href="http://www.w3.org/2001/04/xmlenc#%7DEncryptedData" target="_blank">http://www.w3.org/2001/04/xmlenc#}EncryptedData</a></div>


<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child element ({<a href="http://www.w3.org/2001/04/xmlenc#%7DEncryptedData" target="_blank">http://www.w3.org/2001/04/xmlenc#}EncryptedData</a>)</div>

<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling DOM element (EncryptedData)</div>
<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling attributes for DOM element (EncryptedData)</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: processing generic attribute</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: processing generic attribute</div>


<div><br></div><div>...</div><div><br></div><div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject.Builder [1]: located XMLObjectBuilder for element name: {<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherData" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherData</a></div>


<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child element ({<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherData" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherData</a>)</div><div>

2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling DOM element (CipherData)</div>
<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child nodes of DOM element (CipherData)</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject.Builder [1]: located XMLObjectBuilder for element name: {<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherValue" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherValue</a></div>


<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child element ({<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherValue" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherValue</a>)</div><div>

2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling DOM element (CipherValue)</div>
<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child nodes of DOM element (CipherValue)</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: processing text content at position (0)</div><div>


2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject.Builder [1]: located XMLObjectBuilder for element name: {<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherData" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherData</a></div>

<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child element ({<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherData" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherData</a>)</div>
<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling DOM element (CipherData)</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child nodes of DOM element (CipherData)</div><div>


2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject.Builder [1]: located XMLObjectBuilder for element name: {<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherValue" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherValue</a></div>

<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child element ({<a href="http://www.w3.org/2001/04/xmlenc#%7DCipherValue" target="_blank">http://www.w3.org/2001/04/xmlenc#}CipherValue</a>)</div>
<div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling DOM element (CipherValue)</div><div>2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: unmarshalling child nodes of DOM element (CipherValue)</div><div>


2012-07-20 17:21:50 DEBUG XMLTooling.XMLObject [1]: processing text content at position (0)</div></div><div><br></div><div>and then after the last one of those, I see:</div><div><br></div><div>012-07-20 17:22:02 INFO Shibboleth.Listener [1]: detected socket closure, shutting down worker thread</div>


<div><br></div><div>I don&#39;t see any actual errors anywhere, but I do know from looking at the transaction log that none of the encrypted data is being used for anything (the transaction log shows no activity).  Do I have to do something on the Attribute definitions (in my extractor) to tell them to decrypt attributes, or does that happen automagically?</div>


<div><br></div><div>Thanks,</div><div><br></div><div>Rob</div><div><div><br><div class="gmail_quote">On Fri, Jul 20, 2012 at 12:54 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>


<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>&gt; So there appear to be attributes, but my SP is unable to decrypt them. From<br>
&gt; reading the docs, I found that the &lt;AttributeExtractor&gt; will support<br>
&gt; &lt;saml2:EncryptedAttribute&gt; elements, but I see we are getting<br>
&gt; &lt;saml:EncryptedAttribute&gt;. Could this be causing us to not properly handle<br>
&gt; the elements?<br>
<br>
</div>No, not unless that prefix isn&#39;t declared somewhere to be the right namespace. If it&#39;s not handling them, there should be logs indicating why, but I don&#39;t know that this has ever been tested. I can&#39;t recall whether I ever tried it in an interop event, and the IdP we have doesn&#39;t support the feature (only at the assertion level).<br>



<div><br>
&gt; Also, on ApplicationDefaults, I have encrypted=true (which I<br>
&gt; think only applies to outbound messages though)<br>
<br>
</div>It does.<br>
<div><br>
&gt; PS: I would like to add that of all the open source message boards I have<br>
&gt; used, the shib folks respond the fastest, hands down. Thank you for that.<br>
<br>
</div>Thank you for noticing.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br></div></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>