<div dir="ltr">This is very generalize but basically CAS only shifts the primary authority token (the user name) over to Shibboleth which typically uses it as the principal name to resolve and retrieve other attributes. At APU, even though CAS releases more attributes than username, Shibboleth is only aware of the main attribute (user name) which I believe is sent over as a session variable. Shibboleth uses another data source (LDAP, DBMS) to look up the additional attributes for the authenticated user.</div>

<div class="gmail_extra"><br clear="all"><div><font face="tahoma, sans-serif"><div><font face="tahoma, sans-serif"><br></font></div>Joshua Riffle</font><div><font face="tahoma, sans-serif">Software Engineer<br></font><div>

<font color="#CC0000" face="tahoma, sans-serif"><b>Azusa Pacific University</b></font></div></div></div>
<br><br><div class="gmail_quote">On Mon, Apr 8, 2013 at 9:54 AM, Stein, Eric <span dir="ltr">&lt;<a href="mailto:steine@locustec.com" target="_blank">steine@locustec.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

Okay, so whatever I can convince CAS to put in will come out of Shibboleth with no further tinkering?<br>
<br>
Does Shibboleth put the username in by default, or do I have to flip a switch somewhere? If by default, how do I see it? I&#39;m dumping all the headers, attributes, etc from a shibbolized app, and I don&#39;t see it.<br>


<br>
Thanks,<br>
Eric Stein<br>
<div class="HOEnZb"><div class="h5"><br>
-----Original Message-----<br>
From: <a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [mailto:<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>] On Behalf Of Cantor, Scott<br>
Sent: Monday, April 08, 2013 12:52 PM<br>
To: Shib Users<br>
Subject: Re: Providing attributes from CAS<br>
<br>
On 4/8/13 12:48 PM, &quot;Stein, Eric&quot; &lt;<a href="mailto:steine@locustec.com">steine@locustec.com</a>&gt; wrote:<br>
<br>
&gt;I&#39;m running Shibboleth IdP with CAS 3.5.1 as my authentication provider.<br>
&gt;I&#39;d like to provide a username attribute (and possibly others later) to<br>
&gt;SPs. What is the right way to tackle this? I assume I need CAS to<br>
&gt;somehow make the attribute available to Shibboleth, but that runs<br>
&gt;contrary to the documentation I found<br>
&gt;(<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAddAttribute" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAddAttribute</a>).<br>
<br>
Well, the username is built-in, otherwise it depends on how the data is made available from CAS, on which I cannot comment.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>