<div dir="ltr">Hi all,<div><br></div><div>how I can force Shibboleth to send response with assertions that I have defined in <i>attribute-resolver.xml</i>. I would like to send back sn, cn, uid and one custom field that I have defined in LDAP. I am using LDAP connector. When my SP initiate FSSO, I am redirected to the Shibboleth login page. User is authenticated. SAML response is send back. But it is without assertions thta I am expecting. What is wrong ?</div>
<div><br></div><div><b>In attribute-resolver.xml, here are defined attributes :</b></div><div><br></div><div><div><span style="white-space:pre">    </span>&lt;resolver:AttributeDefinition xsi:type=&quot;ad:Simple&quot; id=&quot;uid&quot; sourceAttributeID=&quot;userid&quot;&gt;</div>
<div>        &lt;resolver:Dependency ref=&quot;myLDAP&quot; /&gt;</div><div>        &lt;resolver:AttributeEncoder xsi:type=&quot;enc:SAML1String&quot; name=&quot;urn:mace:dir:attribute-def:uid&quot; /&gt;</div><div>        &lt;resolver:AttributeEncoder xsi:type=&quot;enc:SAML2String&quot; name=&quot;urn:oid:0.9.2342.19200300.100.1.1&quot; friendlyName=&quot;uid&quot; /&gt;</div>
<div>    &lt;/resolver:AttributeDefinition&gt;</div><div><span style="white-space:pre">        </span><br></div><div><span class="" style="white-space:pre">        </span>&lt;resolver:AttributeDefinition xsi:type=&quot;ad:Simple&quot; id=&quot;cpqd&quot; sourceAttributeID=&quot;cpqd&quot;&gt;</div>
<div>        &lt;resolver:Dependency ref=&quot;myLDAP&quot; /&gt;</div><div><span class="" style="white-space:pre">                </span>&lt;resolver:AttributeEncoder xsi:type=&quot;enc:SAML1String&quot; name=&quot;cpqd&quot; /&gt;</div>
<div><span class="" style="white-space:pre">                </span>&lt;resolver:AttributeEncoder xsi:type=&quot;enc:SAML2String&quot; name=&quot;cpqd&quot; /&gt;</div><div>    &lt;/resolver:AttributeDefinition&gt;</div><div><br></div><div style>
<b>In attribute-filter.xml I have the following lines :</b></div><div style><b><br></b></div><div style><div>    &lt;!--  Release the transient ID, espa &amp; eptid to anyone --&gt;</div><div>    &lt;afp:AttributeFilterPolicy id=&quot;releaseToAnyone&quot;&gt;</div>
<div>        &lt;afp:PolicyRequirementRule xsi:type=&quot;basic:ANY&quot;/&gt;</div><div><br></div><div><span class="" style="white-space:pre">        </span>&lt;!-- Transient --&gt;</div><div>        &lt;afp:AttributeRule attributeID=&quot;transientId&quot;&gt;</div>
<div>            &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;</div><div>        &lt;/afp:AttributeRule&gt;</div><div><span class="" style="white-space:pre">                </span></div><div><span class="" style="white-space:pre">        </span>&lt;!-- uid to ANY --&gt;</div>
<div><span class="" style="white-space:pre">        </span>&lt;afp:AttributeRule attributeID=&quot;uid&quot;&gt;</div><div>            &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot; /&gt;</div><div>        &lt;/afp:AttributeRule&gt;</div>
<div><span class="" style="white-space:pre">                </span></div><div><span class="" style="white-space:pre">        </span>&lt;afp:AttributeRule attributeID=&quot;cpqd&quot;&gt;</div><div>            &lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot; /&gt;</div>
<div>        &lt;/afp:AttributeRule&gt;</div><div><br></div><div>    &lt;/afp:AttributeFilterPolicy&gt;</div></div><div><br></div> </div><div style>And I am not getting these attributes. I am missing something ?</div><div style>
<br></div><div style>One note. In my LDAP names are the same and all are lowercase. I have tried also with <strong>lowercaseAttributeNames </strong> in LDAP connector.</div><div style><br></div><div style>Thank you,</div>
<div style>Rastko</div><div>
<br></div></div>

<br>
<a href="http://www.calliduscloudconnections.com/" rel="nofollow" style="color:rgb(0,51,204);text-decoration:underline;background-image:none;background-color:rgb(255,255,255);border-bottom-style:none;font-family:Arial,Verdana,sans-serif;font-size:13px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:21px;text-align:left;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-repeat:initial initial" target="_blank"><img alt="CallidusCloud Connections" src="https://sites.google.com/a/calliduscloud.com/callidus-signature-site/_/rsrc/1355957960088/c3-signature-addition/c3_sig_2.png" style="border:0px;padding:0px" border="0"></a><span style="color:rgb(68,68,68);font-family:Arial,Verdana,sans-serif;font-size:13px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:21px;text-align:left;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);display:inline!important;float:none"> CallidusCloud Connections, Las Vegas, May 5-7, 2013,<span> </span></span><font style="font-family:Arial,Verdana,sans-serif;font-size:13px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:21px;text-align:left;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255)" color="#ff9900"><a href="http://www.calliduscloudconnections.com/register.html" rel="nofollow" style="color:rgb(0,51,204);text-decoration:underline" target="_blank">REGISTER NOW</a></font>