<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div>OK, in retrospect this seems fairly obvious, as often seems the case for me and Shib.</div><div><br></div><div>I had had to define a custom relying party config for Transact, in which I included the SSO profile - the only one I thought needed. Given my belated realization that their process relies on a follow-up attribute query, I needed the AttributeQuery profile added to that custom relying party config. </div><div><br></div><div>Once that was added, the Transact portal reports successful authN and correct values of attributes from the IdP.</div><div><br></div><div>Thanks to Andrew Keating, Nate Klingenstein, Mike Grady for replies <span style="background-color: rgba(255, 255, 255, 0);">impedance-matched to me.</span></div><div><br><div>David.Bantz<span class="Apple-style-span" style="-webkit-composition-fill-color: rgba(175, 192, 227, 0.231373);">@<a href="http://Alaska.edu">Alaska.edu</a></span><div><span class="Apple-style-span" style="-webkit-composition-fill-color: rgba(175, 192, 227, 0.230469); -webkit-composition-frame-color: rgba(77, 128, 180, 0.230469);"><br></span></div></div></div><div><br>On Oct 23, 2014, at 6:11 AM, Nate Klingenstein <<a href="mailto:ndk@internet2.edu">ndk@internet2.edu</a>> wrote:<br><br></div><blockquote type="cite"><div>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
Probably just need to add AttributeQuery for that relying party. Give it a shot.
<div><br>
<div>
<div>On Oct 23, 2014, at 6:48 AM, David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<br>
<div>
<div>On Oct 23, 2014, at 3:00, Nate Klingenstein <<a href="mailto:ndk@internet2.edu">ndk@internet2.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div>
<blockquote type="cite"><span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;">I
don’t understand. What makes sense?</span></blockquote>
<div><br>
</div>
<div>It makes sense that you're encountering this error.</div>
<br>
<blockquote type="cite">Andrew suggested we have the handler commented out, but as I replied, we don’t.
<div style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<div>Is there something wrong with this handler:</div>
</div>
</blockquote>
</div>
<br>
<div>I'm thinking context. Which element is it in? Is it in a custom RelyingParty, a DefaultRelyingParty?</div>
</div>
</blockquote>
<br>
</div>
<div><br>
</div>
<div>Hmmm. </div>
<div><br>
</div>
<div>It (the attribute query profile below) is in handler.xml in the profile group.</div>
<div><br>
</div>
<div>The vendor has a custom relying party config in relying-party.xml. </div>
<div><br>
</div>
<div>Based on your question, do I infer I need an additional or different clause in the custom relying party to refer to the attribute query profile?</div>
<div><br>
</div>
<div>in handler.xml</div>
<div><br>
</div>
<div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
<ProfileHandler xsi:type="SAML2AttributeQuery"</div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
inboundBinding="urn:oasis:names:tc:SAML:2.0:bindings:<span style="color: #fffac2; background-color: #000000">SOAP</span>"</div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
outboundBindingEnumeration="urn:oasis:names:tc:SAML:2.0:bindings:<span style="color: #fffac2; background-color: #000000">SOAP</span>"></div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
<RequestPath>/SAML2/<span style="color: #fffac2; background-color: #000000">SOAP</span>/AttributeQuery</RequestPath></div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
</ProfileHandler></div>
<div><br>
</div>
<div>in relying-party.xml</div>
<div><br>
</div>
<div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
<RelyingParty id="<a href="https://sp/">https://sp</a>.<span style="color: #fffac2; background-color: #000000">trans</span><a href="http://actsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt">actsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt</a>"</div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
provider="urn:mace:incommon:alaska.edu"</div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
defaultSigningCredentialRef="IdPCredential"</div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
defaultAuthenticationMethod="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"></div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
<ProfileConfiguration xsi:type="saml:SAML2SSOProfile" encryptAssertions="never" encryptNameIds="never" /></div>
<div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">
</RelyingParty></div>
</div>
<div><br>
</div>
</div>
<div></div>
</div>
</blockquote>
</div>
<br>
</div>
</div></blockquote></body></html>