<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<div>
<div style="font-family:Calibri,sans-serif; font-size:11pt">Attributes should be mapped between Shibboleth and ADFS.<br>
there is a guide in the howto section of the adfs site on TechNet.<br>
Jean Marie<br>
Envoyé depuis un mobile<br>
</div>
</div>
<hr>
<span style="font-family:Tahoma,sans-serif; font-size:10pt; font-weight:bold">De :
</span><span style="font-family:Tahoma,sans-serif; font-size:10pt">Cantor, Scott</span><br>
<span style="font-family:Tahoma,sans-serif; font-size:10pt; font-weight:bold">Envoyé :
</span><span style="font-family:Tahoma,sans-serif; font-size:10pt">07/10/2012 20:32</span><br>
<span style="font-family:Tahoma,sans-serif; font-size:10pt; font-weight:bold">À&nbsp;:
</span><span style="font-family:Tahoma,sans-serif; font-size:10pt">Shib Users</span><br>
<span style="font-family:Tahoma,sans-serif; font-size:10pt; font-weight:bold">Objet :
</span><span style="font-family:Tahoma,sans-serif; font-size:10pt">Re: Shibboleth IDP and ADFS federation claim problem</span><br>
<br>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On 10/6/12 3:36 AM, &quot;Renzo De Renzi&quot; &lt;renzos@me.com&gt; wrote:<br>
<br>
&gt;I've a working shibboleth IDP and SP on the same local machine<br>
&gt;(192.168.0.210) and now I installed ADFS under a W2K8R2/IIS machine<br>
&gt;(192.168.0.220). Under ADFS I added a claims provider trust in order to<br>
&gt;use the shibboleth IDP to authenticate users that try to access a web<br>
&gt;page under W2K8R2/IIS. The federation appears to be enabled with ADFS but<br>
&gt;the shibboleth offered claims types is empty and the federation doesn't<br>
&gt;work. It sounds strange for me because the shibboleth IDP works well with<br>
&gt;the Shibboleth SP on the same local machine and I'm able to print on<br>
&gt;screen the attributes after I log in, but on the federated Windows<br>
&gt;machine.<br>
<br>
There are few similarities between the very standards-based SAML attribute<br>
profiles used by Shibboleth and the proprietary, often fundamentally<br>
incorrect, approaches to attribute naming used by ADFS. If you want to use<br>
ADFS as an SP, you have to adjust the IdP or the ADFS side to use one or<br>
the other, and that can be very complex on the ADFS side.<br>
<br>
Some of this is discussed in the wiki in the CommercialInterop topic.<br>
<br>
You have to start by determining how you intend to name attributes in SAML<br>
and work from that to what configuration changes are needed.<br>
<br>
If you follow up with some information on what attributes you want to<br>
exchange, and then which end you want to adjust, then there are more<br>
specific examples available.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>