<div dir="ltr">Dear all,<div><br></div><div style>We have a problem extracting user attributes from a our client&#39;s IDP. The authentication succeeds but no attributes are pushed/resolved.</div><div style><br></div><div style>

The SP is actually working with many other IDPs from the same federation. The IDP has also been tested with other resources from the federation with success.</div><div style>Additionnaly, The aacli.sh command executed by the client returns the attributes.<br>

</div><div style><br></div><div style>The syslog below shows that </div><div style>1 / no attributes are pushed during SSO (do you confirm ?)</div><div style>2 / the attribute resolution fails... This is because there&#39;s no &quot;AttributeAuthorityDescriptor&quot; in the IDP&#39;s metadata (see <a href="https://lists.internet2.edu/sympa/arc/shibboleth-users/2009-06/msg00040.html">discussion</a>).</div>

<div style><br></div><div style>Any idea on how to solve this issue ? Is it a certificate issue ?</div><div style><br></div><div style>Please advice,</div><div style><br></div><div style>Thanks</div><div style><br></div>
<div style>
<br></div><div style><div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG XMLTooling.KeyInfoResolver.Inline [12]: <b>resolved 0 certificate(s)</b></font></div><div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG XMLTooling.CredentialCriteria [12]: <b>key algorithm didn&#39;t match (&#39;AES&#39; != &#39;RSA&#39;)</b></font></div>

<div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG XMLTooling.KeyInfoResolver.Inline [12]: resolving ds:X509Certificate</font></div><div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG XMLTooling.KeyInfoResolver.Inline [12]: resolved 1 certificate(s)</font></div>

<div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG Shibboleth.SSO.SAML2 [12]: decrypted Assertion: &lt;saml:Assertion xmlns:saml=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot; ID=&quot;_1d175dede02b33fdda56b541aa1044db&quot; IssueInstant=&quot;2013-01-30T15:22:44.630Z&quot; Version=&quot;2.0&quot;&gt;&lt;saml:Issuer Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:entity&quot;&gt;<a href="https://shibbo.ec-nantes.fr/idp/shibboleth">https://shibbo.ec-nantes.fr/idp/shibboleth</a>&lt;/saml:Issuer&gt;&lt;saml:Subject&gt;&lt;saml:SubjectConfirmation Method=&quot;urn:oasis:names:tc:SAML:2.0:cm:bearer&quot;&gt;&lt;saml:SubjectConfirmationData Address=&quot;195.68.4.238&quot; InResponseTo=&quot;_f811fc94ba2bdf931a8b7c604f198928&quot; NotOnOrAfter=&quot;2013-01-30T15:27:44.630Z&quot; Recipient=&quot;<a href="https://controller.mobile.lan/Shibboleth.sso/SAML2/POST">https://controller.mobile.lan/Shibboleth.sso/SAML2/POST</a>&quot;/&gt;&lt;/saml:SubjectConfirmation&gt;&lt;/saml:Subject&gt;&lt;saml:Conditions NotBefore=&quot;2013-01-30T15:22:44.630Z&quot; NotOnOrAfter=&quot;2013-01-30T15:27:44.630Z&quot;&gt;&lt;saml:AudienceRestriction&gt;&lt;saml:Audience&gt;<a href="https://www.ucopia.com/shib">https://www.ucopia.com/shib</a>&lt;/saml:Audience&gt;&lt;/saml:AudienceRestriction&gt;&lt;/saml:Conditions&gt;&lt;saml:AuthnStatement AuthnInstant=&quot;2013-01-30T15:22:44.405Z&quot; SessionIndex=&quot;f9b1016452c9fb52fc85c1e0f7487bea7db08f2e8ecfd1aff8150de5574cb856&quot;&gt;&lt;saml:SubjectLocality Address=&quot;195.68.4.238&quot;/&gt;&lt;saml:AuthnContext&gt;&lt;saml:AuthnContextDeclRef&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&lt;/saml:AuthnContextDeclRef&gt;&lt;/saml:AuthnContext&gt;&lt;/saml:AuthnStatement&gt;&lt;/saml:Assertion&gt;</font></div>

<div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG Shibboleth.SSO.SAML2 [12]: extracting issuer from SAML 2.0 assertion</font></div><div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [12]: evaluating message flow policy (replay checking on, expiration 60)</font></div>

<div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG XMLTooling.StorageService [12]: inserted record (_1d175dede02b33fdda56b541aa1044db) in context (MessageFlow)</font></div><div>

<font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [12]: assertion satisfied bearer confirmation requirements</font></div><div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG Shibboleth.SSO.SAML2 [12]: SSO profile processing completed successfully</font></div>

<div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG Shibboleth.SSO.SAML2 [12]: <b>extracting pushed attributes...</b></font></div><div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 DEBUG Shibboleth.SSO.SAML2 [12]: <b>resolving attributes...</b></font></div>

<div><font face="courier new, monospace">Jan 30 16:22:44 localhost shibboleth: 1359559364 WARN Shibboleth.AttributeResolver.Query [12]: <b>can&#39;t attempt attribute query, either no NameID or no metadata to use</b></font></div>

<div><br></div><div style><br></div><div><br></div></div></div>