<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Sorry a few more details I forgot to mention:<div><br></div><div>1. We are an SP and the changes shown below are for the SP.</div><div>2. We also have not enabled SSL between our &nbsp;loadbalancer and Apache/Shibboleth &nbsp;and we do have warning messages in shibd_warn.log&nbsp;</div><div><br></div><div><span style="font-size: 12pt; ">2012-10-01 15:20:59 WARN Shibboleth.Application :
insecure cookieProps setting, set to "https" for SSL/TLS-only usage</span>

<p class="MsoPlainText">2012-10-01 15:20:59 WARN Shibboleth.Application :
handlerSSL should be enabled for SSL/TLS-enabled web sites</p>

<p class="MsoPlainText">2012-10-01 15:20:59 WARN Shibboleth.PropertySet :
deprecation - remapping property (defaultACSIndex) to (acsIndex)</p>

<p class="MsoPlainText">2012-10-01 15:20:59 WARN Shibboleth.PropertySet :
deprecation - remapping property (defaultACSIndex) to (acsIndex)</p><p class="MsoPlainText"><br></p><p class="MsoPlainText">We have SSL upto the load balancer(F5)</p><p class="MsoPlainText"><br></p><p class="MsoPlainText">Thanks</p><p class="MsoPlainText">Jayashree</p><p class="MsoPlainText"><br></p><p class="MsoPlainText"><br></p><p class="MsoPlainText"><br></p><p class="MsoPlainText"><br></p><div><div id="SkyDrivePlaceholder"></div><hr id="stopSpelling">From: jravi123@hotmail.com<br>To: users@shibboleth.net<br>Subject: Adding SAML2 ACS points does not seem to map attributes from SAML2 IDP<br>Date: Mon, 1 Oct 2012 19:27:08 +0000<br><br>

<style><!--
.ExternalClass .ecxhmmessage P
{padding:0px;}
.ExternalClass body.ecxhmmessage
{font-size:12pt;font-family:Calibri;}

--></style>
<div dir="ltr">Hello.<div><br></div><div>We added SAML2 endpoints to support SAML2 IDP's &nbsp;We do receive the attributes from the IDP in the response which we see in the signature.log file as well. However we do not see any reference to attributes in transaction.log and also we see the following error message in native.log. Not sure if these are related.</div><div><br></div><div><br></div><div>shib_handler: invalid acsIndex property, or non-SAML 1.x ACS, using default SAML 1.x ACS</div><div>shib_handler: socket call (unknown) resulted in error (32): no message</div><div><br></div><div>Our shibboleth2.xml file has the following tags added to support SAML2</div><div><br></div><div><p class="ecxMsoPlainText">&lt;SessionInitiator type="Chaining"
Location="/Login"</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;id="Login"
relayState="cookie"&gt;</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;SessionInitiator type="Shib1"
defaultACSIndex="1" /&gt;</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;SessionInitiator type="SAML2"
template="bindingTemplate.html"
outgoingBindings="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST </p>

<p class="ecxMsoPlainText">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
defaultACSIndex="2" /&gt;</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/SessionInitiator&gt;</p>

<p class="ecxMsoPlainText">&nbsp;</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;md:AssertionConsumerService Location="/SAML/POST"</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
index="3"
Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" /&gt;</p>

<p class="ecxMsoPlainText">&nbsp;</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;md:AssertionConsumerService Location="/SAML2/POST"
index="1"</p>

<p class="ecxMsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/&gt;</p></div><div><br></div><div><br></div><div>We are able to receive attributes from the existing SAML1 customers but we not SAML2 customers.</div><div><br></div><div><br></div><div>Any help would be appreciated.</div><div><br></div><div>Thanks</div><div>Jayashree</div><div><br></div><div><br></div>                                               </div>
<br>--
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div></div>                                               </div></body>
</html>