<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Tahoma","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">Hi there<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">I’ve setup a new (2.5.2) Service Provider under Server 2008 / IIS 7.5. The basics are tested, and I’ve setup the following attribute-filter definition (the same as it was
for our old 2.4.2 SP, but with the requesterString updated):<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <AttributeFilterPolicy><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <!-- Login folder for Heritage sites--><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <PolicyRequirementRule xsi:type="basic:AttributeRequesterString" value="https://heritage.hull-college.ac.uk/shibboleth" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <AttributeRule attributeID="eduPersonPrincipalName"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <PermitValueRule xsi:type="basic:ANY" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> </AttributeRule><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <!--location information in this one: --><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <AttributeRule attributeID="eduPersonOrgDN"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> <PermitValueRule xsi:type="basic:ANY" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> </AttributeRule><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> </AttributeFilterPolicy><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">This published them as HTTP_EPPN and HTTP_ORGDN.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">However, 2.5.2 doesn’t want to interpret the ORGDN bit (EPPN is coming through fine, to HTTP_EPPN if I run a PHP script to spit out all the $_SERVER headers) even though it
acknowledges there is an attribute – but it doesn’t like that attribute, so here’s a cranked up DEBUG including the (decoded) assertion:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.TrustEngine.ExplicitKey [2]: attempting to validate signature with the peer's credentials<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.TrustEngine.ExplicitKey [2]: signature validated with credential<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [2]: signature verified against message issuer<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SSO.SAML2 [2]: processing message against SAML 2.0 SSO profile<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.CredentialCriteria [2]: key algorithm didn't match ('AES' != 'RSA')<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SSO.SAML2 [2]: decrypted Assertion: <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_d22b0fc787915f870a56a0a366727fc7"
IssueInstant="2013-09-30T14:32:46.298Z" Version="2.0"><saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://shibb.hull-college.ac.uk/idp/shibboleth</saml2:Issuer><saml2:Subject><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier="https://shibb.hull-college.ac.uk/idp/shibboleth" SPNameQualifier="https://heritage.hull-college.ac.uk/shibboleth">_116b36fb647ed7e4ae193cd685ad2b5f</saml2:NameID><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData
Address="192.168.180.200" InResponseTo="_71c182c565c70256b0ae8d775828ec6c" NotOnOrAfter="2013-09-30T14:37:46.298Z" Recipient="http://heritage.hull-college.ac.uk/Shibboleth.sso/SAML2/POST"/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions NotBefore="2013-09-30T14:32:46.298Z"
NotOnOrAfter="2013-09-30T14:37:46.298Z"><saml2:AudienceRestriction><saml2:Audience>https://heritage.hull-college.ac.uk/shibboleth</saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement AuthnInstant="2013-09-30T14:32:45.219Z" SessionIndex="de97341b53b66b7a9727ef430c2c9d31f67cbcd9a980b4a3963a214d69fdaadf"><saml2:SubjectLocality
Address="192.168.180.200"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement><saml2:AttributeStatement><saml2:Attribute
FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xs:string">70012521@hull-college.ac.uk</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonOrgDN" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue
xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">cn=70012521,ou=Admin,ou=Qngn,o=hull_coll</saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SSO.SAML2 [2]: extracting issuer from SAML 2.0 assertion<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.StorageService [2]: inserted record (_d22b0fc787915f870a56a0a366727fc7) in context (MessageFlow) with expiration (1380551806)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2]: assertion satisfied bearer confirmation requirements<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SSO.SAML2 [2]: SSO profile processing completed successfully<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SSO.SAML2 [2]: extracting pushed attributes...<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.AttributeExtractor.XML [2]: unable to extract attributes, unknown XML object type: saml2p:Response<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.AttributeExtractor.XML [2]: skipping unmapped NameID with format (urn:oasis:names:tc:SAML:2.0:nameid-format:transient)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.AttributeExtractor.XML [2]: unable to extract attributes, unknown XML object type: saml2:AuthnStatement<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.AttributeDecoder.Scoped [2]: decoding ScopedAttribute (eppn) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.6) with 1 value(s)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 INFO Shibboleth.AttributeExtractor.XML [2]: skipping unmapped SAML 2.0 Attribute with Name: urn:oid:1.3.6.1.4.1.5923.1.1.1.3<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.AttributeFilter [2]: filtering 1 attribute(s) from (https://shibb.hull-college.ac.uk/idp/shibboleth)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.AttributeFilter [2]: applying filtering rule(s) for attribute (eppn) from (https://shibb.hull-college.ac.uk/idp/shibboleth)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SSO.SAML2 [2]: resolving attributes...<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.AttributeResolver.Query [2]: found AttributeStatement in input to new session, skipping query<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SessionCache [2]: creating new session<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SessionCache [2]: storing new session...<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.StorageService [2]: inserted record (session) in context (_7b29d82fbc7a62bca914fbe184701f98) with expiration (1380555145)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.StorageService [2]: inserted record (_116b36fb647ed7e4ae193cd685ad2b5f) in context (NameID) with expiration (1380580345)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.StorageService [2]: inserted record (_d22b0fc787915f870a56a0a366727fc7) in context (_7b29d82fbc7a62bca914fbe184701f98) with expiration
(1380555145)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 INFO Shibboleth.SessionCache [2]: new session created: ID (_7b29d82fbc7a62bca914fbe184701f98) IdP (https://shibb.hull-college.ac.uk/idp/shibboleth) Protocol(urn:oasis:names:tc:SAML:2.0:protocol)
Address (127.0.0.1)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG XMLTooling.StorageService [2]: deleted record (f854f2c721754b77fb619fd6440945e529ba0ff09c79ad5a6ab2051b0eeab422) in context (RelayState)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">2013-09-30 15:32:25 DEBUG Shibboleth.SSO.SAML2 [2]: ACS returning via redirect to: http://heritage.hull-college.ac.uk/secure/hello.php<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">Any ideas appreciated.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">Thanks,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">Dave<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""><o:p> </o:p></span></p>
<div style="mso-element:para-border-div;border:none;border-bottom:solid windowtext 1.5pt;padding:0cm 0cm 1.0pt 0cm">
<p class="MsoNormal" style="border:none;padding:0cm"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black;mso-fareast-language:EN-GB">David Perry<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black;mso-fareast-language:EN-GB">eLearning Technologist, Hull College Group<br>
<br>
Room L34 - Queens Gardens Library<br>
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black;mso-fareast-language:EN-GB">Extension 2230 / Direct Dial 01482 381930<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
Message scanned
<p><span style="font-family:'Arial';font-size:8pt;">**********************************************************************</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">This message is sent in confidence for the addressee</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">only. It may contain confidential or sensitive</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">information. The contents are not to be disclosed</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">to anyone other than the addressee. Unauthorised</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">recipients are requested to preserve this</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">confidentiality and to advise us of any errors in</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">transmission. Any views expressed in this message</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">are solely the views of the individual and do not</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">represent the views of the College. Nothing in this</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">message should be construed as creating a contract.</span></p>
<p><span style="font-family:'Arial';font-size:8pt;"> </span></p>
<p><span style="font-family:'Arial';font-size:8pt;">Hull College owns the email infrastructure, including the contents.</span></p>
<p><span style="font-family:'Arial';font-size:8pt; color:#000000;"> </span></p>
<p><span style="font-family:'Arial';font-size:8pt; color:#000000;">Hull College is committed to sustainability, please reflect before printing this email.</span></p>
<p><span style="font-family:'Arial';font-size:8pt;">**********************************************************************</span></p>
<p><span style="font-family:'Arial';font-size:8pt;"></span></p>
<p><span style="font-family:'Arial';font-size:8pt;"> </span></p>
<p><span style="font-family:'Arial';font-size:8pt;"> </span></p></body>
</html>