<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<br>
<br>
<div class="moz-cite-prefix">W dniu 24.03.2015 o 12:14, Rod
Widdowson pisze:<br>
</div>
<blockquote
cite="mid:00ad01d06623$ad3ae130$07b0a390$@steadingsoftware.com"
type="cite">
<blockquote type="cite">
<pre wrap="">Releasing attributes to SAML2 SPs works.
</pre>
</blockquote>
<pre wrap="">
To clarify, does that mean that SP is demanding SAML1? The metadata I'm looking at suggests not at first blush.</pre>
</blockquote>
It seems that while going to my Shib 3 IdP ticket.iop.org uses
SAML1. <br>
I have in the log <br>
2015-03-24 12:39:05,229 - DEBUG [PROTOCOL_MESSAGE:166] - <br>
SAML 1 IdP-initiated request was:
IdPInitiatedSSORequest{entityId=<a class="moz-txt-link-freetext" href="https://ticket.iop.org/shibboleth">https://ticket.iop.org/shibboleth</a>,
acsURL=<a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML/POST">https://ticket.iop.org/Shibboleth.sso/SAML/POST</a>,
relayState=cookie:534566a6, time=2015-03-24T11:39:04.000Z}<br>
and then IdP produces <saml1p:response> and send it to <br>
<br>
I have the production IdP running simplesamlphp and there all works
good. SAML tracer shows that first <samlp:AuthnRequest..> is
sent, then <samlp:Response> and the POST goes to SAML2
endpoint<br>
<small><a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML2/POST">https://ticket.iop.org/Shibboleth.sso/SAML2/POST</a></small><br>
<br>
<blockquote
cite="mid:00ad01d06623$ad3ae130$07b0a390$@steadingsoftware.com"
type="cite">
<pre wrap="">
But then they also appear to be being doing something odd with discovery to do with per federation responses, and then end up with a Shibboleth (SAML1) query.
I've just tested a SAML1 sp against a V3 IdP (with attribute pull) and it did "what I expected" (show attribute screen and then release them), so it's not a simple bug.
More by way of straw-grasping, can you force the artefact profile and see what happens:
<youtIdP>/idp/profile/Shibboleth/SSO?shire=https%3A%2F%2Fticket.iop.org%2FShibboleth.sso%2FSAML%2FArtifact&target=cookie%3A015f5922&providerId=https%3A%2F%2Fticket.iop.org%2Fshibboleth
</pre>
</blockquote>
With this request I'm getting an error from
<a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML/Artifact">https://ticket.iop.org/Shibboleth.sso/SAML/Artifact</a>...:<br>
<h1><small><small>opensaml::BindingException</small></small></h1>
<p>The system encountered an error at Tue Mar 24 11:18:49 2015
</p>
<p>To report this problem, please contact the site administrator at
<a href="mailto:custserv@iop.org">custserv@iop.org</a>.
</p>
<p>Please include the following message in any email:</p>
<p class="error">opensaml::BindingException at
(<a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML/Artifact">https://ticket.iop.org/Shibboleth.sso/SAML/Artifact</a>)</p>
<p>Unable to resolve artifact(s) into a SAML response.</p>
<br>
Maja<br>
<blockquote
cite="mid:00ad01d06623$ad3ae130$07b0a390$@steadingsoftware.com"
type="cite">
<pre wrap="">
</pre>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Maja Gorecka-Wolniewicz <a class="moz-txt-link-abbreviated" href="mailto:mgw@umk.pl">mgw@umk.pl</a>
Uczelniane Centrum Information & Communication
Informatyczne Technology Centre
Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University
Coll. Maximum, pl. Rapackiego 1, 87-100 Torun, Poland
tel.: +48 56-611-27-40 fax: +48 56-622-18-50 tel. kom.: +48-693032574</pre>
</body>
</html>