<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>Il giorno 09/ott/2012, alle ore 15:59, Cantor, Scott ha scritto:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div>On 10/9/12 1:57 AM, "Renzo De Renzi" &lt;<a href="mailto:renzos@me.com">renzos@me.com</a>&gt; wrote:<br><blockquote type="cite"><br></blockquote><blockquote type="cite">Thanks for your prompt answer, this is my policy taken from<br></blockquote><blockquote type="cite">attribute-filter-xml file, it already works correctly between Shibboleth<br></blockquote><blockquote type="cite">IDP and SP on the same machine:<br></blockquote><br>Those are not SAML attributes, they're internal to the IdP. You have to<br>decide if you want to use standard names for them, or ADFS' proprietary<br>names. Then you have to change one end or the other.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></div></blockquote></div><br><div>Hi good evening,<br>unfortunately after 20 days still no luck, I can't manage to make the Shibboleth IDP - ADFS SP working.<br>I set up a Claim-aware Web App under VS2010 that correctly runs under the ADFS domain and prints out some claims after the authentication. Now I would like to use the Shibboleth IDP that releases 3 claims, one of which is the givenName. I added the Shibboleth IDP under ADFS 2.0 and set up this rule:<br><br>c:[Type == "<a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname</a>"]<br>=&gt; issue(Type = "urn:oid:2.5.4.42", Value = c.Value, Properties["<a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claimp">http://schemas.xmlsoap.org/ws/2005/05/identity/claimp</a>roperties/attributename"] = "urn:oasis:names:tc:SAML:2.0:attrname-format:uri");<br><br>Then I launched the WIF Federation utility Wizard to estabilish the trust relationship between my Web App and the Shibboleth IDP but when I select the STS WS_Federation metadata document location (idp-metadata.xml) I get an ID1018 Error (The WS-Federation metadata document does not contain a security token service descriptor.<br><br>Here my idp-metadata.xml file:<br><br><br>&lt;?xml version="1.0" encoding="UTF-8" ?&gt;&nbsp;<br>- &lt;EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" entityID="<a href="https://idp.example.org/shibboleth">https://idp.example.org/shibboleth</a>"&gt;<br>- &lt;IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"&gt;<br>- &lt;Extensions&gt;<br>&nbsp;&lt;shibmd:Scope regexp="false"&gt;example.org&lt;/shibmd:Scope&gt;&nbsp;<br>&nbsp;&lt;/Extensions&gt;<br>- &lt;KeyDescriptor&gt;<br>- &lt;ds:KeyInfo&gt;<br>- &lt;ds:X509Data&gt;<br>&nbsp;&lt;ds:X509Certificate&gt;MIIDJzCCAg+gAwIBAgIUHf2v/KXrNrvx64FbF6ZY9rnHPdAwDQYJKoZIhvcNAQEF BQAwGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMB4XDTEyMDcyNDA4MDUwNFoX DTMyMDcyNDA4MDUwNFowGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmHBXmj+VcDVa5TzcuNRZrRpDF9M5 zJyTHuaC4sjdmPixndC5IyHkk7vLAw22dbwhMry4y1xfX3s8X9+kajRJXJOmQ0rP 4JIcv71ywoLpbrOBnsfiGFWQgNQlOTJJdY7WpOc1f+n3+2Uoi+f4F/IKG8c0jEmg NnwRNFGqK3XlbwCuQMahif+2GHPD7intyJMDr6R67PAOx8AtqxGXCnKP6LmdZofT GZRMrH786PNVCnEn78tguUcMlVVdkYAjF1rqntJOnIeIzsEZowXqSa2keQ7Q/5Jm 47UKjzJFagrE15mkcI/JU5SuDQ1F5hYGhn05fhwhg39sJ4Zv2vvaKUI7kwIDAQAB o2UwYzBCBgNVHREEOzA5gg9pZHAuZXhhbXBsZS5vcmeGJmh0dHBzOi8vaWRwLmV4 YW1wbGUub3JnL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBT+fFTBiudO7jqc62h6 T0wbUfwLVjANBgkqhkiG9w0BAQUFAAOCAQEASC6n3sB/733OI8dD3IfoWLESo1wZ OFz1fGmTOKD2M5+HyVCdpRNvy3tqL1E8Gpnqcrmb4uzIbBa8yFV9wpUFotOz2Frq 9tgFn6XcjLjrTJ7LZE6C7zcf5vyIr2Ke+1zJwxmfPJOo3zS9pdXsug84jokd8NU+ omdo47MrseS8wzKMZU8MDe8cpXFz00pkiPjKram8QGrt7Ut8cV0mzxgPCb6xeWL6 kdNN/qioQP3iV7DIbM5+9d1vlI606hrUTNirqRd3aMlzt4syNwY4+8KFTqgiFont yAY+WrxO9aD9qrB/X/ZoCZO5Snvog31ICafkPBSR0zhm4lYYl1MEqtsWXw==&lt;/ds:X509Certificate&gt;&nbsp;<br>&nbsp;&lt;/ds:X509Data&gt;<br>&nbsp;&lt;/ds:KeyInfo&gt;<br>&nbsp;&lt;/KeyDescriptor&gt;<br>&nbsp;&lt;ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="<a href="https://idp.example.org:8443/idp/profile/SAML1/SOAP/ArtifactResolution">https://idp.example.org:8443/idp/profile/SAML1/SOAP/ArtifactResolution</a>" index="1" /&gt;&nbsp;<br>&nbsp;&lt;ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://idp.example.org:8443/idp/profile/SAML2/SOAP/ArtifactResolution">https://idp.example.org:8443/idp/profile/SAML2/SOAP/ArtifactResolution</a>" index="2" /&gt;&nbsp;<br>&nbsp;&lt;NameIDFormat&gt;urn:mace:shibboleth:1.0:nameIdentifier&lt;/NameIDFormat&gt;&nbsp;<br>&nbsp;&lt;NameIDFormat&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&lt;/NameIDFormat&gt;&nbsp;<br>&nbsp;&lt;SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="<a href="https://idp.example.org/idp/profile/Shibboleth/SSO">https://idp.example.org/idp/profile/Shibboleth/SSO</a>" /&gt;&nbsp;<br>&nbsp;&lt;SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://idp.example.org/idp/profile/SAML2/POST/SSO">https://idp.example.org/idp/profile/SAML2/POST/SSO</a>" /&gt;&nbsp;<br>&nbsp;&lt;SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="<a href="https://idp.example.org/idp/profile/SAML2/POST-SimpleSign/SSO">https://idp.example.org/idp/profile/SAML2/POST-SimpleSign/SSO</a>" /&gt;&nbsp;<br>&nbsp;&lt;SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://idp.example.org/idp/profile/SAML2/Redirect/SSO">https://idp.example.org/idp/profile/SAML2/Redirect/SSO</a>" /&gt;&nbsp;<br>&nbsp;&lt;/IDPSSODescriptor&gt;<br>- &lt;AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"&gt;<br>- &lt;Extensions&gt;<br>&nbsp;&lt;shibmd:Scope regexp="false"&gt;example.org&lt;/shibmd:Scope&gt;&nbsp;<br>&nbsp;&lt;/Extensions&gt;<br>- &lt;KeyDescriptor&gt;<br>- &lt;ds:KeyInfo&gt;<br>- &lt;ds:X509Data&gt;<br>&nbsp;&lt;ds:X509Certificate&gt;MIIDJzCCAg+gAwIBAgIUHf2v/KXrNrvx64FbF6ZY9rnHPdAwDQYJKoZIhvcNAQEF BQAwGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMB4XDTEyMDcyNDA4MDUwNFoX DTMyMDcyNDA4MDUwNFowGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmHBXmj+VcDVa5TzcuNRZrRpDF9M5 zJyTHuaC4sjdmPixndC5IyHkk7vLAw22dbwhMry4y1xfX3s8X9+kajRJXJOmQ0rP 4JIcv71ywoLpbrOBnsfiGFWQgNQlOTJJdY7WpOc1f+n3+2Uoi+f4F/IKG8c0jEmg NnwRNFGqK3XlbwCuQMahif+2GHPD7intyJMDr6R67PAOx8AtqxGXCnKP6LmdZofT GZRMrH786PNVCnEn78tguUcMlVVdkYAjF1rqntJOnIeIzsEZowXqSa2keQ7Q/5Jm 47UKjzJFagrE15mkcI/JU5SuDQ1F5hYGhn05fhwhg39sJ4Zv2vvaKUI7kwIDAQAB o2UwYzBCBgNVHREEOzA5gg9pZHAuZXhhbXBsZS5vcmeGJmh0dHBzOi8vaWRwLmV4 YW1wbGUub3JnL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBT+fFTBiudO7jqc62h6 T0wbUfwLVjANBgkqhkiG9w0BAQUFAAOCAQEASC6n3sB/733OI8dD3IfoWLESo1wZ OFz1fGmTOKD2M5+HyVCdpRNvy3tqL1E8Gpnqcrmb4uzIbBa8yFV9wpUFotOz2Frq 9tgFn6XcjLjrTJ7LZE6C7zcf5vyIr2Ke+1zJwxmfPJOo3zS9pdXsug84jokd8NU+ omdo47MrseS8wzKMZU8MDe8cpXFz00pkiPjKram8QGrt7Ut8cV0mzxgPCb6xeWL6 kdNN/qioQP3iV7DIbM5+9d1vlI606hrUTNirqRd3aMlzt4syNwY4+8KFTqgiFont yAY+WrxO9aD9qrB/X/ZoCZO5Snvog31ICafkPBSR0zhm4lYYl1MEqtsWXw==&lt;/ds:X509Certificate&gt;&nbsp;<br>&nbsp;&lt;/ds:X509Data&gt;<br>&nbsp;&lt;/ds:KeyInfo&gt;<br>&nbsp;&lt;/KeyDescriptor&gt;<br>&nbsp;&lt;AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="<a href="https://idp.example.org:8443/idp/profile/SAML1/SOAP/AttributeQuery">https://idp.example.org:8443/idp/profile/SAML1/SOAP/AttributeQuery</a>" /&gt;&nbsp;<br>&nbsp;&lt;AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://idp.example.org:8443/idp/profile/SAML2/SOAP/AttributeQuery">https://idp.example.org:8443/idp/profile/SAML2/SOAP/AttributeQuery</a>" /&gt;&nbsp;<br>&nbsp;&lt;NameIDFormat&gt;urn:mace:shibboleth:1.0:nameIdentifier&lt;/NameIDFormat&gt;&nbsp;<br>&nbsp;&lt;NameIDFormat&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&lt;/NameIDFormat&gt;&nbsp;<br>&nbsp;&lt;/AttributeAuthorityDescriptor&gt;<br>&nbsp;&lt;/EntityDescriptor&gt;</div></body></html>