<HTML><HEAD></HEAD>
<BODY dir=ltr>
<DIV dir=ltr>
<DIV style="FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: 12pt">
<DIV>
<DIV
style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"></DIV> </DIV>
<DIV
style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none">
<DIV dir=ltr>
<DIV style="FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: 12pt">
<DIV align=justify>
<DIV
style="FONT-STYLE: normal; DISPLAY: inline; FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: small; FONT-WEIGHT: normal; TEXT-DECORATION: none"></DIV>
<DIV style="FONT-FAMILY: 'Calibri'; COLOR: #000000; FONT-SIZE: 12pt" dir=ltr
align=justify>
<DIV align=justify>Hello everyone, </DIV>
<DIV align=justify> </DIV>
<DIV align=justify>My name is Sergio and it’s a pleasure for me being part of
this mailing list. I’d like to apologize about my English, which isn’t very good
but I’ll do my best to explain my problem.</DIV>
<DIV align=justify> </DIV>
<DIV align=justify>I’ve been working with Shibboleth during these days to create
a basic SSO service with a protected directory (just trying to protect “secure”
default directory). Although I’ve followed all the steps shown in the official
documentation and even in some web sites over the Internet, I haven’t been able
to get it work properly.</DIV>
<DIV align=justify> </DIV>
<DIV align=justify>I’m using a User / Password authentication with an LDAP
connector, and it seems to work as I can enter bad credentials and I’m not
authorizated to access the service (i.e., the login form is showing). The
problem is that I always get this message when my user is correctly
authenticated:</DIV>
<DIV align=justify> </DIV>
<DIV align=justify> </DIV>
<DIV align=justify>"We're sorry, but you cannot access this service at this
time. </DIV>
<DIV align=justify> </DIV>
<DIV align=justify>This service requires information about you that your
identity provider did not release. To gain access to this service, your identity
provider must release the required information.</DIV>
<DIV align=justify> </DIV>
<DIV align=justify>You were trying to access the following URL: </DIV>
<DIV align=justify> </DIV>
<DIV align=justify> <A
href="https://sp1.semi.com/secure">https://sp1.semi.com/secure</A></DIV>
<DIV align=justify> </DIV>
<DIV align=justify>For more information about this service, including what user
information is required for access, please visit our information page."</DIV>
<DIV align=justify> </DIV>
<DIV align=justify> </DIV>
<DIV align=justify>I’ve reviewed all the configs and everything seems correct. I
even tried “aacli.sh” script on IdP to check if it was releasing the attributes
I selected correctly, and it seems to work (I get commonName + surname
attributes with a correct user, and no attributes with an incorrect user).</DIV>
<DIV align=justify> </DIV>
<DIV align=justify>What do you think, guys? </DIV>
<DIV align=justify> </DIV>
<DIV align=justify>Let me know if you need additional information, like OS
using, Shibboleth version and so on.</DIV>
<DIV align=justify> </DIV>
<DIV align=justify>Thank you in advance. </DIV>
<DIV align=justify> </DIV>
<DIV align=justify>Kind Regards, </DIV>
<DIV align=justify>Sergio. </DIV>
<DIV> </DIV></DIV></DIV></DIV></DIV></DIV></DIV></DIV></BODY></HTML>