<meta http-equiv=Content-Type content="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]--><o:SmartTagType
 namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="State"/>
<o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags"
 name="place"/>
<!--[if !mso]>
<style>
st1\:*{behavior:url(#default#ieooui) }
</style>
<![endif]-->






<div class=Section1>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'>On 8/19/2012 5:44 PM, csross wrote: <o:p></o:p></span></font></p>

<div>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><br>
&gt; On 8/19/12 3:00 PM, &quot;csross&quot; &lt;[hidden email]
&lt;/user/SendEmail.jtp?type=node&amp;node=7581375&amp;i=0&gt;&gt; wrote: <br>
&gt; &nbsp;&gt; <br>
&gt; &nbsp;&gt;I have to talk to a new IDP with a new SP on my shib 2.4.3
solaris <br>
&gt; &nbsp;&gt;server. <br>
&gt; &nbsp;&gt;I believe the IDP is opensso and the administrator does not have
any <br>
&gt; &nbsp;&gt;experience with shibboleth as they never had any SPs running it.
They sent <br>
&gt; &nbsp;&gt;me a metadata.xml file which I specified identified in the
shibboleth2.xml <br>
&gt; &nbsp;&gt;file. &nbsp;They also sent me an extended metadata.xml file
which has a number <br>
&gt; &nbsp;&gt;of <br>
&gt; &nbsp;&gt;Attritribute name= and value. &nbsp;These look nothing like what
is in the <br>
&gt; &nbsp;&gt;attribute-map.xml file I use for other IDPs I contact but they
run <br>
&gt; &nbsp;&gt;Shibboleth. <br>
&gt; <br>
&gt; &nbsp;&gt;&gt;&gt;The SP doesn't use any of that particular information in
metadata. <br>
&gt; <br>
&gt; &nbsp;&gt;&gt;&gt;Obviously the attributes they're sending do have to be
mapped but that <br>
&gt; doesn't involve the metadata. <br>
&gt; <br>
&gt; Thank you. &nbsp;Has anyone done this, manually created a mapping for
attributes passed from another SSO-ipd into a format shibboleth understands
please? &nbsp;If there is a doc on this, I would greatly <br>
&gt; appreciate the link. &nbsp;I know it depends on what attribute they are
sending, etc, but a generic example would be great. <br>
&gt; <font color=navy><span style='color:navy'><o:p></o:p></span></font></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>THANK YOU VERY MUCH.&nbsp; <o:p></o:p></span></font></p>

<p class=MsoNormal><font size=3 color=navy face="Times New Roman"><span
style='font-size:12.0pt;color:navy'><o:p>&nbsp;</o:p></span></font></p>

<p class=MsoNormal><font size=3 color=navy face="Times New Roman"><span
style='font-size:12.0pt;color:navy'>&gt;&gt;&gt;&gt;</span></font>I have done
this as a test, with opensso as the idp. <br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt;</span></font>There
was nothing special with the metadata file. <br>
<font color=navy><span style='color:navy'>Do I use the extended metadata file
at all or just the non-extended file please?&nbsp; <o:p></o:p></span></font></p>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt;</span></font>But in
the SP attribute-map.xml file I uncommented the section: <br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt;</span></font>&nbsp;
&lt;!--Examples of LDAP-based attributes, uncomment to use these... --&gt; <br>
<br>
<font color=navy><span style='color:navy'><o:p></o:p></span></font></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>I do not know about LDAP so I will see
about adding something like this to the bottom of the map file.&nbsp; Some
research showed the need for AttritributeDecoder.&nbsp; Did you have to do
anything with that please?<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt;</span></font>&nbsp;
and added: <br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt;</span></font>&nbsp;
&nbsp; &nbsp;&lt;Attribute name=&quot;urn:mace:dir:attribute-def:uid&quot;
id=&quot;uid&quot;/&gt; <br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt;</span></font>&nbsp;
&nbsp; &nbsp;&lt;Attribute name=&quot;urn:oid:0.9.2342.19200300.100.1.1&quot;
id=&quot;uid&quot;/&gt; <br>
<br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt; </span></font>In the
shibboleth2.xml file, since OpenSSO does not return a eppn, <br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt; </span></font>but
only a uid (unscoped) &nbsp;I change the REMOTE_USER= <br>
<br>
<font color=navy><span style='color:navy'><o:p></o:p></span></font></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>The admin for the IDP sent me a screenshot
of NamdID Format Current Values.&nbsp; Do you know if I have to do anything
with this?&nbsp; I hate GUIs.<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p>&nbsp;</o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>urn:oasis:names:tc:SAML:2.0:nameid-format:transient<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>urn:oasis:names:tc:SAML:1.0:nameid-format:unspecified<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt; </span></font>REMOTE_USER=&quot;eppn
uid persistent-id targeted-id&quot; <br>
<br>
<font color=navy><span style='color:navy'>&gt;&gt;&gt;&gt; </span></font>So in
our case, opensso sends LDAP attrubutes including givenName, sn, cn and uid. <font
color=navy><span style='color:navy'><o:p></o:p></span></font></span></font></p>

</div>

<div>

<p class=MsoNormal><font size=3 color=navy face="Times New Roman"><span
style='font-size:12.0pt;color:navy'><o:p>&nbsp;</o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>Again, thank you.&nbsp; This has been
helpful.<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p>&nbsp;</o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>Christine<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><br>
&gt; <br>
&gt; &nbsp;&gt;A lot of sites I researched mentioned NameIDFormat and I see
these in the <br>
&gt; &nbsp;&gt;metadata.xml and extended-metadata.xml, &nbsp;but again it is in
an unfamilar <br>
&gt; &nbsp;&gt;format. &nbsp;Is there any relation to the entries in
attritbute-map? <br>
&gt; <br>
&gt; &nbsp;&gt;&gt;&gt;No. <br>
&gt; <br>
&gt; &nbsp;&gt;Does anyone have any idea how to incorporate this into
Shibboleth please? <br>
&gt; <br>
&gt; &nbsp;&gt;&gt;&gt;You don't need to. <br>
&gt; <br>
&gt; -- Scott <br>
&gt; <br>
&gt; -- <br>
&gt; To unsubscribe from this list send an email to [hidden email]
&lt;/user/SendEmail.jtp?type=node&amp;node=7581375&amp;i=1&gt; <br>
&gt; <br>
&gt; <br>
&gt; <br>
&gt; <br>
&gt; _______________________________________________ <br>
&gt; If you reply to this email, your message will be added to the discussion
below: <br>
&gt; <a
href="http://shibboleth.1660669.n2.nabble.com/incorporating-opensso-metadata-and-extended-metadata-xml-files-into-shibboleth-SP-tp7581372p7581374.html"
target="_top" link="external" rel="nofollow">http://shibboleth.1660669.n2.nabble.com/incorporating-opensso-metadata-and-extended-metadata-xml-files-into-shibboleth-SP-tp7581372p7581374.html</a><br>
&gt; <br>
&gt; To unsubscribe from incorporating opensso metadata and extended metadata
xml files into shibboleth SP, visit <br>
&gt; <br>
&gt; <br>
&gt;
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
<br>
&gt; View this message in context: RE: incorporating opensso metadata and
extended metadata xml files into shibboleth SP <br>
&gt; &lt;<a
href="http://shibboleth.1660669.n2.nabble.com/incorporating-opensso-metadata-and-extended-metadata-xml-files-into-shibboleth-SP-tp7581372p7581375.html"
target="_top" link="external" rel="nofollow">http://shibboleth.1660669.n2.nabble.com/incorporating-opensso-metadata-and-extended-metadata-xml-files-into-shibboleth-SP-tp7581372p7581375.html</a>&gt;
<br>
&gt; Sent from the Shibboleth - Users mailing list archive &lt;<a
href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html"
target="_top" link="external" rel="nofollow">http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html</a>&gt;
at Nabble.com. <br>
&gt; <br>
&gt; <br>
&gt; -- <br>
&gt; To unsubscribe from this list send an email to <a
href="/user/SendEmail.jtp?type=node&amp;node=7581382&amp;i=0" target="_top" link="external" rel="nofollow">[hidden email]</a> <br>
&gt; <o:p></o:p></span></font></p>

</div>

<p class=MsoNormal style='margin-bottom:12.0pt'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'><br>
-- <br>
<br>
&nbsp; Douglas E. Engert &nbsp;&lt;<a
href="/user/SendEmail.jtp?type=node&amp;node=7581382&amp;i=1" target="_top" link="external" rel="nofollow">[hidden email]</a>&gt; <br>
&nbsp; Argonne National Laboratory <br>
&nbsp; 9700 South Cass Avenue <br>
&nbsp; Argonne, <st1:State w:st="on"><st1:place w:st="on">Illinois</st1:place></st1:State>
&nbsp;60439 <br>
&nbsp; (630) 252-5444 <br>
<br>
<br>
-- <br>
To unsubscribe from this list send an email to <a
href="/user/SendEmail.jtp?type=node&amp;node=7581382&amp;i=2" target="_top" link="external" rel="nofollow">[hidden email]</a> <br>
<br>
<o:p></o:p></span></font></p>

<div class=MsoNormal align=center style='text-align:center'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'>

<hr size=1 width="100%" noshade color="#cccccc" align=center>

</span></font></div>

<div>

<div>

<p class=MsoNormal><b><font size=1 color="#444444" face=Tahoma><span
style='font-size:9.0pt;font-family:Tahoma;color:#444444;font-weight:bold'>If
you reply to this email, your message will be added to the discussion below:<o:p></o:p></span></font></b></p>

</div>

<p class=MsoNormal><font size=1 color="#444444" face=Tahoma><span
style='font-size:9.0pt;font-family:Tahoma;color:#444444'><a
href="http://shibboleth.1660669.n2.nabble.com/incorporating-opensso-metadata-and-extended-metadata-xml-files-into-shibboleth-SP-tp7581372p7581382.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/incorporating-opensso-metadata-and-extended-metadata-xml-files-into-shibboleth-SP-tp7581372p7581382.html</a>
<o:p></o:p></span></font></p>

</div>

<div style='margin-top:4.8pt'>

<p class=MsoNormal style='line-height:18.0pt'><font size=1 color="#666666"
face=Tahoma><span style='font-size:8.5pt;font-family:Tahoma;color:#666666'>To
unsubscribe from incorporating opensso metadata and extended metadata xml files
into shibboleth SP, <a
href="" target="_top" rel="nofollow" link="external">click
here</a>.<br>
<a
href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&amp;id=instant_html%21nabble%3Aemail.naml&amp;base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&amp;breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external"><font
size=1 face="Times New Roman"><span style='font-size:7.0pt;font-family:"Times New Roman"'>NAML</span></font></a>
<o:p></o:p></span></font></p>

</div>

</div>






        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/incorporating-opensso-metadata-and-extended-metadata-xml-files-into-shibboleth-SP-tp7581372p7581384.html">RE: incorporating opensso metadata and extended metadata xml files into shibboleth SP</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>