Hi, and thanks again!<br><br><div class="gmail_quote">On Wed Dec 03 2014 at 2:49:32 PM Cantor, Scott &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">You didn&#39;t say what was in the log, so I don&#39;t know.<br></blockquote><div><br></div><div>Of course you couldn&#39;t -- my bad for not providing sufficient detail.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">No, that&#39;s in the XML. I&#39;m talking about what the SP is doing with it. If<br>
you don&#39;t have a mapping rule for something it sees, it will log that it&#39;s<br>
been skipped. And the tran log shows exactly what it did extract and<br>
cache, and the Session dumping handler shows roughly the same thing.<br></blockquote><div><br></div><div>So all this means...that shibd is getting the XML, and unpacking it, and then not knowing what to do with the mapping?</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
&gt;And in my attribute-map.xml, I have (not commented out)<br>
&gt;     &lt;Attribute name=&quot;urn:oid:0.9.2342.<u></u>19200300.100.1.1&quot; id=&quot;uid&quot;<br>
&gt;NameFormat=&quot;urn:oasis:names:<u></u>tc:SAML:2.0:attrname-format:<u></u>uri&quot; /&gt;<br>
&gt;and<br>
&gt;    &lt;Attribute name=&quot;urn:oid:1.3.6.1.4.1.<u></u>5923.1.1.1.11&quot; id=&quot;assurance&quot;/&gt;<br>
Then you should have clear log evidence and session dump evidence that<br>
they&#39;re there.<br></blockquote><div><br></div><div>In which log might I find these? What other knobs can I twiddle to find these? </div><div><br></div><div>In shibd.logger, I have pretty much everything set to DEBUG</div><div><br></div><div>The transaction log has many lines like</div><div><div>2014-12-03 14:46:48 INFO Shibboleth-TRANSACTION [5]: New session (ID: _13032dbfdee80993f655dfc5597c686c) with (applicationId: default) for principal from (IdP: <a href="https://idp.testshib.org/idp/shibboleth">https://idp.testshib.org/idp/shibboleth</a>) at (ClientAddress: a.b.c.d) with (NameIdentifier: _55ca2e3ca8fc071da6bf1ecb76d36e8e) using (Protocol: urn:oasis:names:tc:SAML:2.0:protocol) from (AssertionID: _b7d624b7035aecf9caabcf4f36344e57)</div><div>2014-12-03 14:46:48 INFO Shibboleth-TRANSACTION [5]: Cached the following attributes with session (ID: _13032dbfdee80993f655dfc5597c686c) for (applicationId: default) {</div><div>2014-12-03 14:46:48 INFO Shibboleth-TRANSACTION [5]: }</div></div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
&gt;But there are no variables at all...thus my confusion.<br>
You can&#39;t get the other variables and not get the attributes, so that<br>
suggests to me you&#39;re not actually mapping the attributes that you think<br>
you are, but there are ways to tell.<br></blockquote><div><br></div><div>How can I tell? I&#39;m breathless with debugging-anticipation! :-) </div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">One possibility is you changed the attribute map and didn&#39;t restart<br>
things. The map does not reload by default, unlike most of the<br>
configuration.<br></blockquote><div><br></div><div>I have bounced shibd many times, but I can bounce it one more. </div><div><br></div><div>Once again, thanks for your patience and help with a shibbo-noob.</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
-- Scott</blockquote><div><br></div><div>//jbaltz </div></div>