<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns:p="urn:schemas-microsoft-com:office:powerpoint" xmlns:a="urn:schemas-microsoft-com:office:access" xmlns:dt="uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s="uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs="urn:schemas-microsoft-com:rowset" xmlns:z="#RowsetSchema" xmlns:b="urn:schemas-microsoft-com:office:publisher" xmlns:ss="urn:schemas-microsoft-com:office:spreadsheet" xmlns:c="urn:schemas-microsoft-com:office:component:spreadsheet" xmlns:odc="urn:schemas-microsoft-com:office:odc" xmlns:oa="urn:schemas-microsoft-com:office:activation" xmlns:html="http://www.w3.org/TR/REC-html40" xmlns:q="http://schemas.xmlsoap.org/soap/envelope/" xmlns:rtc="http://microsoft.com/officenet/conferencing" xmlns:D="DAV:" xmlns:Repl="http://schemas.microsoft.com/repl/" xmlns:mt="http://schemas.microsoft.com/sharepoint/soap/meetings/" xmlns:x2="http://schemas.microsoft.com/office/excel/2003/xml" xmlns:ppda="http://www.passport.com/NameSpace.xsd" xmlns:ois="http://schemas.microsoft.com/sharepoint/soap/ois/" xmlns:dir="http://schemas.microsoft.com/sharepoint/soap/directory/" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:dsp="http://schemas.microsoft.com/sharepoint/dsp" xmlns:udc="http://schemas.microsoft.com/data/udc" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:sub="http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/" xmlns:ec="http://www.w3.org/2001/04/xmlenc#" xmlns:sp="http://schemas.microsoft.com/sharepoint/" xmlns:sps="http://schemas.microsoft.com/sharepoint/soap/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:udcs="http://schemas.microsoft.com/data/udc/soap" xmlns:udcxf="http://schemas.microsoft.com/data/udc/xmlfile" xmlns:udcp2p="http://schemas.microsoft.com/data/udc/parttopart" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns:st="&#1;" xmlns="http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=Content-Type content="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
        {font-family:Mangal;
        panose-1:2 4 5 3 5 2 3 3 2 2;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.5pt;
        font-family:Consolas;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:Consolas;}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
.MsoChpDefault
        {mso-style-type:export-only;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
        {page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext="edit">
  <o:idmap v:ext="edit" data="1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=EN-US link=blue vlink=purple>

<div class=Section1>

<p class=MsoPlainText>Hello,<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>I have made changes back to original in
Attribute_resolver.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp; resolver:AttributeDefinition
xsi:type=&quot;ad:TransientId&quot; id=&quot;transientId&quot;&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp; &lt;resolver:AttributeEncoder
xsi:type=&quot;enc:SAML1StringNameIdentifier&quot;
nameFormat=&quot;urn:mace:shibboleth:1.0:nameIdentifier&quot;/&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp; &lt;resolver:AttributeEncoder
xsi:type=&quot;enc:SAML2StringNameID&quot;
nameFormat=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&quot;/&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp; &lt;/resolver:AttributeDefinition&gt;<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>and now Just having filter in <o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><u>Attribute Filter</u>.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule
attributeID=&quot;transientId&quot;&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/afp:AttributeRule&gt;<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;afp:AttributeRule attributeID=&quot;mail&quot;&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/afp:AttributeRule&gt;<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;afp:AttributeRule attributeID=&quot;cn&quot;&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;afp:PermitValueRule xsi:type=&quot;basic:ANY&quot;/&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/afp:AttributeRule&gt;<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>Still getting Attribute transientId was not encoded
because no SAML2AttributeEncoder was attached to it.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><u>My Ldap Config that are working fine in Login.config
are </u>(I am succesfully loggin in using them)<o:p></o:p></p>

<p class=MsoPlainText><u><o:p><span style='text-decoration:none'>&nbsp;</span></o:p></u></p>

<p class=MsoPlainText>ldapUrl=&quot;ldap://192.168.0.138&quot;<o:p></o:p></p>

<p class=MsoPlainText>baseDn=&quot;CN=Users,DC=fcsjpr,DC=com&quot;<o:p></o:p></p>

<p class=MsoPlainText>bindDn=&quot;CryoserverJournal&quot;<o:p></o:p></p>

<p class=MsoPlainText>bindCredential=&quot;jpr0123&quot;<o:p></o:p></p>

<p class=MsoPlainText>subtreeSearch=&quot;true&quot;<o:p></o:p></p>

<p class=MsoPlainText>ssl=&quot;false&quot;<o:p></o:p></p>

<p class=MsoPlainText>userField=&quot;userPrincipalName&quot;;<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><b><u>Below is the Setting that I am using in attribute
resolver.<o:p></o:p></u></b></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp; &lt;resolver:DataConnector
id=&quot;myLDAP&quot; xsi:type=&quot;dc:LDAPDirectory&quot;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
ldapURL=&quot;ldap://192.168.0.138&quot; <o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
baseDN=&quot;cn=Users,dc=fcsjpr,dc=com&quot;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
principal=&quot;cn=CryoserverJournal,cn=Users,dc=fcsjpr,dc=com&quot;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
principalCredential=&quot; jpr0123&quot;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; lowercaseAttributeNames =
&quot;true&quot;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;dc:FilterTemplate&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;![CDATA[<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; (cn=${requestContext.principalName})<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
]]&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/dc:FilterTemplate&gt;<o:p></o:p></p>

<p class=MsoPlainText>&nbsp;&nbsp;&nbsp; &lt;/resolver:DataConnector&gt;<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>I am not sur what wroing I am doing?<o:p></o:p></p>

<p class=MsoPlainText>Please help.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>Thanks and Regards<o:p></o:p></p>

<p class=MsoPlainText>Saurabh Tyagi<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>-----Original Message-----<o:p></o:p></p>

<p class=MsoPlainText>From: users-bounces@shibboleth.net
[mailto:users-bounces@shibboleth.net] On Behalf Of Peter Schober<o:p></o:p></p>

<p class=MsoPlainText>Sent: Thursday, June 27, 2013 6:04 PM<o:p></o:p></p>

<p class=MsoPlainText>To: users@shibboleth.net<o:p></o:p></p>

<p class=MsoPlainText>Subject: Re: Fetch Attributes From SAML IdP<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>* Saurabh Tyagi &lt;<a
href="mailto:saurabh.tyagi@thepsi.com">saurabh.tyagi@thepsi.com</a>&gt;
[2013-06-27 13:10]:<o:p></o:p></p>

<p class=MsoPlainText>&gt; I am trying to fetch certain values from Ldap that
is connected to Idp.<o:p></o:p></p>

<p class=MsoPlainText>&gt; <o:p></o:p></p>

<p class=MsoPlainText>&gt; I am unable to understand how to do that. I tried
reading articles. <o:p></o:p></p>

<p class=MsoPlainText>&gt; <o:p></o:p></p>

<p class=MsoPlainText>&gt; I have made some changes if any one of u can please
confirm if I am moving<o:p></o:p></p>

<p class=MsoPlainText>&gt; in right direction.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>Undo all the changes you've made and it will mostly Just
Work.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&gt; Attribute-resolver :- (Added two fields to be
fetched from Ldap)<o:p></o:p></p>

<p class=MsoPlainText>&gt; <o:p></o:p></p>

<p class=MsoPlainText>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;resolver:AttributeDefinition xsi:type=&quot;ad:Simple&quot;<o:p></o:p></p>

<p class=MsoPlainText>&gt; xmlns=&quot;urn:mace:shibboleth:2.0:attribute:encoder&quot;
id=&quot;mail&quot;<o:p></o:p></p>

<p class=MsoPlainText>&gt; sourceAttributeID=&quot;mail&quot;&gt;<o:p></o:p></p>

<p class=MsoPlainText>&gt; <o:p></o:p></p>

<p class=MsoPlainText>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;resolver:Dependency ref=&quot;myLDAP&quot; /&gt;<o:p></o:p></p>

<p class=MsoPlainText>&gt; <o:p></o:p></p>

<p class=MsoPlainText>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/resolver:AttributeDefinition&gt;<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>As mentioned above.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;resolver:AttributeDefinition xsi:type=&quot;ad:Simple&quot;<o:p></o:p></p>

<p class=MsoPlainText>&gt;
xmlns=&quot;urn:mace:shibboleth:2.0:attribute:encoder&quot; id=&quot;dn&quot;<o:p></o:p></p>

<p class=MsoPlainText>&gt; sourceAttributeID=&quot;dn&quot;&gt;<o:p></o:p></p>

<p class=MsoPlainText>&gt; <o:p></o:p></p>

<p class=MsoPlainText>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;resolver:Dependency ref=&quot;myLDAP&quot; /&gt;<o:p></o:p></p>

<p class=MsoPlainText>&gt; <o:p></o:p></p>

<p class=MsoPlainText>&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&lt;/resolver:AttributeDefinition<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>An LDAP object's &quot;dn&quot; is not an attribute of that
object. Some DSAs<o:p></o:p></p>

<p class=MsoPlainText>chose to expose it as such using the entryDN operation
attribute,<o:p></o:p></p>

<p class=MsoPlainText>which means it will only be returned if (a) the DSA
supports it, (b)<o:p></o:p></p>

<p class=MsoPlainText>you have access to read it, and (c) you explicitly ask
for it in the<o:p></o:p></p>

<p class=MsoPlainText>LDAP DataConnector.<o:p></o:p></p>

<p class=MsoPlainText>But IIRC the vtldap library will allow you to construct a
DN<o:p></o:p></p>

<p class=MsoPlainText>attribute, see the documentation.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&gt; Attribute transientId was not encoded because no<o:p></o:p></p>

<p class=MsoPlainText>&gt; SAML2AttributeEncoder was attached to it.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>The default configuration for transientId works fine and
is<o:p></o:p></p>

<p class=MsoPlainText>sufficient, i.e. undo whatever you did to break it. You
can always<o:p></o:p></p>

<p class=MsoPlainText>compare to the unmodified config files from the IdP
distribution (or<o:p></o:p></p>

<p class=MsoPlainText>VCS).<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.876 - DEBUG
[edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:314]
- Resolving attribute mail for principal <a href="mailto:sam@jpr.com">sam@jpr.com</a><o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.877 - DEBUG
[edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:354]
- Resolving data connector myLDAP for principal <a href="mailto:sam@jpr.com">sam@jpr.com</a><o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.889 - DEBUG
[edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.dataConnector.LdapDataConnector:308]
- Search filter: (uid=$requestContext.userPrincipalName)<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.889 - DEBUG
[edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.dataConnector.LdapDataConnector:363]
- LDAP data connector myLDAP - Retrieving attributes from LDAP<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.889 - DEBUG
[edu.vt.middleware.ldap.handler.DefaultConnectionHandler:74] - Bind with the
following parameters:<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.889 - DEBUG
[edu.vt.middleware.ldap.handler.DefaultConnectionHandler:75] -&nbsp;&nbsp;
authtype = simple<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.889 - DEBUG
[edu.vt.middleware.ldap.handler.DefaultConnectionHandler:76] -&nbsp;&nbsp; dn =
Journal<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.889 - DEBUG
[edu.vt.middleware.ldap.handler.DefaultConnectionHandler:83] -&nbsp;&nbsp;
credential = &lt;suppressed&gt;<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.893 - DEBUG
[edu.vt.middleware.ldap.Ldap:193] - Search with the following parameters:<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.893 - DEBUG
[edu.vt.middleware.ldap.Ldap:194] -&nbsp;&nbsp; dn = cn=Users,dc=jpr,dc=com<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.893 - DEBUG
[edu.vt.middleware.ldap.Ldap:195] -&nbsp;&nbsp; filter =
(uid=$requestContext.userPrincipalName)<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.893 - DEBUG
[edu.vt.middleware.ldap.Ldap:196] -&nbsp;&nbsp; filterArgs = []<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.893 - DEBUG
[edu.vt.middleware.ldap.Ldap:197] -&nbsp;&nbsp; searchControls = <a
href="mailto:javax.naming.directory.SearchControls@18ff27">javax.naming.directory.SearchControls@18ff27</a><o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.893 - DEBUG
[edu.vt.middleware.ldap.Ldap:198] -&nbsp;&nbsp; handler =
[edu.vt.middleware.ldap.handler.FqdnSearchResultHandler@1177115, <a
href="mailto:edu.vt.middleware.ldap.handler.EntryDnSearchResultHandler@150a0">edu.vt.middleware.ldap.handler.EntryDnSearchResultHandler@150a0</a>,
<a
href="mailto:edu.vt.middleware.ldap.handler.CaseChangeSearchResultHandler@546169">edu.vt.middleware.ldap.handler.CaseChangeSearchResultHandler@546169</a>,
<a
href="mailto:edu.vt.middleware.ldap.handler.BinarySearchResultHandler@1c737be">edu.vt.middleware.ldap.handler.BinarySearchResultHandler@1c737be</a>]<o:p></o:p></p>

<p class=MsoPlainText>&gt; 16:34:56.914 - DEBUG<o:p></o:p></p>

<p class=MsoPlainText>&gt;
[edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:336]<o:p></o:p></p>

<p class=MsoPlainText>&gt; - Resolved attribute mail containing 0 values<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>Well, either the object you searched for (<a
href="mailto:uid=sam@jpr.com">uid=sam@jpr.com</a> within<o:p></o:p></p>

<p class=MsoPlainText>cn=Users,dc=jpr,dc=com) for does not exist or it has not
mail<o:p></o:p></p>

<p class=MsoPlainText>attribute (or the binding object does not have
permissions to see the<o:p></o:p></p>

<p class=MsoPlainText>object).<o:p></o:p></p>

<p class=MsoPlainText>Are you sure your uid attribute contains values like
&quot;<a href="mailto:sam@jpr.com">sam@jpr.com</a>&quot;,<o:p></o:p></p>

<p class=MsoPlainText>not just &quot;sam&quot;? No way for anyone else to know.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>So first get the LDAP to return the requested data, using
whatever<o:p></o:p></p>

<p class=MsoPlainText>LDAP tool you want (other than the Shibbololeth IdP).
Once that's<o:p></o:p></p>

<p class=MsoPlainText>working transfer the correct settings to your IDP config.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>Then re-add the encoders which the default config has and
which you removed.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>Then the filter rule you wrote for mail will work.<o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

<p class=MsoPlainText>-peter<o:p></o:p></p>

<p class=MsoPlainText>--<o:p></o:p></p>

<p class=MsoPlainText>To unsubscribe from this list send an email to <a
href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><o:p></o:p></p>

<p class=MsoPlainText><o:p>&nbsp;</o:p></p>

</div>

</body>

</html>