<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle18
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Our side of the house if ADFS IdP so we have no Shibboleth at our site.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Etan Weintraub<br>
<b>Sent:</b> Thursday, January 2, 2014 3:52 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> RE: ADFS to Shibboleth<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Keith-<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Have you tried using Active Directory as your Data Source within your Shibboleth IdP? Or is this just a Shibboleth SP that you are going to from an ADFS IdP?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">-Etan E. Weintraub<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Sr. Systems Engineer<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Directory Architecture<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">IT@Johns Hopkins<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Johns Hopkins at Mt. Washington<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">5801 Smith Ave.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Suite 3110B<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Baltimore, MD 21209<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Phone: 410-735-7945<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">E-mail: <a href="mailto:eweintra@jhmi.edu">
<span style="color:#1F497D">eweintra@jhmi.edu</span></a><o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> <a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [<a href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>Mercer, Keith<br>
<b>Sent:</b> Thursday, January 02, 2014 4:45 PM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<b>Subject:</b> ADFS to Shibboleth<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am trying to see if there is a way to make a rule that would get the LDAP attribute of employeeid from our active directory and then send it as employeeNumber over to Shibboleth? The below are the custom rules needed for employeenumber
that I was thinking that I could possible edit to make work. I am not even sure if something like this is possible.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">c:[Type == "<a href="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname">http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname</a>", Issuer == "AD AUTHORITY"] => add(store = "Active Directory",
types = ("urn:oid:2.16.840.1.113730.3.1.3"), query = ";employeeNumber;{0}", param = c.Value);<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">c:[Type == "urn:oid:2.16.840.1.113730.3.1.3"] => issue(Type = c.Type, Value = c.Value, Issuer = c.Issuer, Properties["<a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/attributename">http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/attributename</a>"]
= "urn:oasis:names:tc:SAML:2.0:attrname-format:uri");<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I thought could change query= to employeeID but that didn’t see to work. I am thinking I would need to do something with the iod’s also. Any assistance would be helpful.<o:p></o:p></p>
</div>
</body>
</html>