<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Hello.<div><br></div><div>We added SAML2 endpoints to support SAML2 IDP's &nbsp;We do receive the attributes from the IDP in the response which we see in the signature.log file as well. However we do not see any reference to attributes in transaction.log and also we see the following error message in native.log. Not sure if these are related.</div><div><br></div><div><br></div><div>shib_handler: invalid acsIndex property, or non-SAML 1.x ACS, using default SAML 1.x ACS</div><div>shib_handler: socket call (unknown) resulted in error (32): no message</div><div><br></div><div>Our shibboleth2.xml file has the following tags added to support SAML2</div><div><br></div><div><p class="MsoPlainText">&lt;SessionInitiator type="Chaining"
Location="/Login"</p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;id="Login"
relayState="cookie"&gt;</p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;SessionInitiator type="Shib1"
defaultACSIndex="1" /&gt;</p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;SessionInitiator type="SAML2"
template="bindingTemplate.html"
outgoingBindings="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST </p>

<p class="MsoPlainText">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
defaultACSIndex="2" /&gt;</p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/SessionInitiator&gt;</p>

<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;md:AssertionConsumerService Location="/SAML/POST"</p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
index="3"
Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" /&gt;</p>

<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;md:AssertionConsumerService Location="/SAML2/POST"
index="1"</p>

<p class="MsoPlainText">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/&gt;</p></div><div><br></div><div><br></div><div>We are able to receive attributes from the existing SAML1 customers but we not SAML2 customers.</div><div><br></div><div><br></div><div>Any help would be appreciated.</div><div><br></div><div>Thanks</div><div>Jayashree</div><div><br></div><div><br></div>                                               </div></body>
</html>