<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>Il giorno 09/ott/2012, alle ore 15:59, Cantor, Scott ha scritto:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div>On 10/9/12 1:57 AM, "Renzo De Renzi" <<a href="mailto:renzos@me.com">renzos@me.com</a>> wrote:<br><blockquote type="cite"><br></blockquote><blockquote type="cite">Thanks for your prompt answer, this is my policy taken from<br></blockquote><blockquote type="cite">attribute-filter-xml file, it already works correctly between Shibboleth<br></blockquote><blockquote type="cite">IDP and SP on the same machine:<br></blockquote><br>Those are not SAML attributes, they're internal to the IdP. You have to<br>decide if you want to use standard names for them, or ADFS' proprietary<br>names. Then you have to change one end or the other.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></div></blockquote></div><br><div>Hi good evening,<br>unfortunately after 20 days still no luck, I can't manage to make the Shibboleth IDP - ADFS SP working.<br>I set up a Claim-aware Web App under VS2010 that correctly runs under the ADFS domain and prints out some claims after the authentication. Now I would like to use the Shibboleth IDP that releases 3 claims, one of which is the givenName. I added the Shibboleth IDP under ADFS 2.0 and set up this rule:<br><br>c:[Type == "<a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname</a>"]<br>=> issue(Type = "urn:oid:2.5.4.42", Value = c.Value, Properties["<a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claimp">http://schemas.xmlsoap.org/ws/2005/05/identity/claimp</a>roperties/attributename"] = "urn:oasis:names:tc:SAML:2.0:attrname-format:uri");<br><br>Then I launched the WIF Federation utility Wizard to estabilish the trust relationship between my Web App and the Shibboleth IDP but when I select the STS WS_Federation metadata document location (idp-metadata.xml) I get an ID1018 Error (The WS-Federation metadata document does not contain a security token service descriptor.<br><br>Here my idp-metadata.xml file:<br><br><br><?xml version="1.0" encoding="UTF-8" ?> <br>- <EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" entityID="<a href="https://idp.example.org/shibboleth">https://idp.example.org/shibboleth</a>"><br>- <IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"><br>- <Extensions><br> <shibmd:Scope regexp="false">example.org</shibmd:Scope> <br> </Extensions><br>- <KeyDescriptor><br>- <ds:KeyInfo><br>- <ds:X509Data><br> <ds:X509Certificate>MIIDJzCCAg+gAwIBAgIUHf2v/KXrNrvx64FbF6ZY9rnHPdAwDQYJKoZIhvcNAQEF BQAwGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMB4XDTEyMDcyNDA4MDUwNFoX DTMyMDcyNDA4MDUwNFowGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmHBXmj+VcDVa5TzcuNRZrRpDF9M5 zJyTHuaC4sjdmPixndC5IyHkk7vLAw22dbwhMry4y1xfX3s8X9+kajRJXJOmQ0rP 4JIcv71ywoLpbrOBnsfiGFWQgNQlOTJJdY7WpOc1f+n3+2Uoi+f4F/IKG8c0jEmg NnwRNFGqK3XlbwCuQMahif+2GHPD7intyJMDr6R67PAOx8AtqxGXCnKP6LmdZofT GZRMrH786PNVCnEn78tguUcMlVVdkYAjF1rqntJOnIeIzsEZowXqSa2keQ7Q/5Jm 47UKjzJFagrE15mkcI/JU5SuDQ1F5hYGhn05fhwhg39sJ4Zv2vvaKUI7kwIDAQAB o2UwYzBCBgNVHREEOzA5gg9pZHAuZXhhbXBsZS5vcmeGJmh0dHBzOi8vaWRwLmV4 YW1wbGUub3JnL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBT+fFTBiudO7jqc62h6 T0wbUfwLVjANBgkqhkiG9w0BAQUFAAOCAQEASC6n3sB/733OI8dD3IfoWLESo1wZ OFz1fGmTOKD2M5+HyVCdpRNvy3tqL1E8Gpnqcrmb4uzIbBa8yFV9wpUFotOz2Frq 9tgFn6XcjLjrTJ7LZE6C7zcf5vyIr2Ke+1zJwxmfPJOo3zS9pdXsug84jokd8NU+ omdo47MrseS8wzKMZU8MDe8cpXFz00pkiPjKram8QGrt7Ut8cV0mzxgPCb6xeWL6 kdNN/qioQP3iV7DIbM5+9d1vlI606hrUTNirqRd3aMlzt4syNwY4+8KFTqgiFont yAY+WrxO9aD9qrB/X/ZoCZO5Snvog31ICafkPBSR0zhm4lYYl1MEqtsWXw==</ds:X509Certificate> <br> </ds:X509Data><br> </ds:KeyInfo><br> </KeyDescriptor><br> <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="<a href="https://idp.example.org:8443/idp/profile/SAML1/SOAP/ArtifactResolution">https://idp.example.org:8443/idp/profile/SAML1/SOAP/ArtifactResolution</a>" index="1" /> <br> <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://idp.example.org:8443/idp/profile/SAML2/SOAP/ArtifactResolution">https://idp.example.org:8443/idp/profile/SAML2/SOAP/ArtifactResolution</a>" index="2" /> <br> <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat> <br> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat> <br> <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="<a href="https://idp.example.org/idp/profile/Shibboleth/SSO">https://idp.example.org/idp/profile/Shibboleth/SSO</a>" /> <br> <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://idp.example.org/idp/profile/SAML2/POST/SSO">https://idp.example.org/idp/profile/SAML2/POST/SSO</a>" /> <br> <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="<a href="https://idp.example.org/idp/profile/SAML2/POST-SimpleSign/SSO">https://idp.example.org/idp/profile/SAML2/POST-SimpleSign/SSO</a>" /> <br> <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://idp.example.org/idp/profile/SAML2/Redirect/SSO">https://idp.example.org/idp/profile/SAML2/Redirect/SSO</a>" /> <br> </IDPSSODescriptor><br>- <AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"><br>- <Extensions><br> <shibmd:Scope regexp="false">example.org</shibmd:Scope> <br> </Extensions><br>- <KeyDescriptor><br>- <ds:KeyInfo><br>- <ds:X509Data><br> <ds:X509Certificate>MIIDJzCCAg+gAwIBAgIUHf2v/KXrNrvx64FbF6ZY9rnHPdAwDQYJKoZIhvcNAQEF BQAwGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMB4XDTEyMDcyNDA4MDUwNFoX DTMyMDcyNDA4MDUwNFowGjEYMBYGA1UEAxMPaWRwLmV4YW1wbGUub3JnMIIBIjAN BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmHBXmj+VcDVa5TzcuNRZrRpDF9M5 zJyTHuaC4sjdmPixndC5IyHkk7vLAw22dbwhMry4y1xfX3s8X9+kajRJXJOmQ0rP 4JIcv71ywoLpbrOBnsfiGFWQgNQlOTJJdY7WpOc1f+n3+2Uoi+f4F/IKG8c0jEmg NnwRNFGqK3XlbwCuQMahif+2GHPD7intyJMDr6R67PAOx8AtqxGXCnKP6LmdZofT GZRMrH786PNVCnEn78tguUcMlVVdkYAjF1rqntJOnIeIzsEZowXqSa2keQ7Q/5Jm 47UKjzJFagrE15mkcI/JU5SuDQ1F5hYGhn05fhwhg39sJ4Zv2vvaKUI7kwIDAQAB o2UwYzBCBgNVHREEOzA5gg9pZHAuZXhhbXBsZS5vcmeGJmh0dHBzOi8vaWRwLmV4 YW1wbGUub3JnL2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBT+fFTBiudO7jqc62h6 T0wbUfwLVjANBgkqhkiG9w0BAQUFAAOCAQEASC6n3sB/733OI8dD3IfoWLESo1wZ OFz1fGmTOKD2M5+HyVCdpRNvy3tqL1E8Gpnqcrmb4uzIbBa8yFV9wpUFotOz2Frq 9tgFn6XcjLjrTJ7LZE6C7zcf5vyIr2Ke+1zJwxmfPJOo3zS9pdXsug84jokd8NU+ omdo47MrseS8wzKMZU8MDe8cpXFz00pkiPjKram8QGrt7Ut8cV0mzxgPCb6xeWL6 kdNN/qioQP3iV7DIbM5+9d1vlI606hrUTNirqRd3aMlzt4syNwY4+8KFTqgiFont yAY+WrxO9aD9qrB/X/ZoCZO5Snvog31ICafkPBSR0zhm4lYYl1MEqtsWXw==</ds:X509Certificate> <br> </ds:X509Data><br> </ds:KeyInfo><br> </KeyDescriptor><br> <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="<a href="https://idp.example.org:8443/idp/profile/SAML1/SOAP/AttributeQuery">https://idp.example.org:8443/idp/profile/SAML1/SOAP/AttributeQuery</a>" /> <br> <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://idp.example.org:8443/idp/profile/SAML2/SOAP/AttributeQuery">https://idp.example.org:8443/idp/profile/SAML2/SOAP/AttributeQuery</a>" /> <br> <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat> <br> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat> <br> </AttributeAuthorityDescriptor><br> </EntityDescriptor></div></body></html>