<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <br>
    <br>
    <div class="moz-cite-prefix">W dniu 24.03.2015 o 12:14, Rod
      Widdowson pisze:<br>
    </div>
    <blockquote
      cite="mid:00ad01d06623$ad3ae130$07b0a390$@steadingsoftware.com"
      type="cite">
      <blockquote type="cite">
        <pre wrap="">Releasing attributes to SAML2 SPs works.
</pre>
      </blockquote>
      <pre wrap="">
To clarify, does that mean that SP is demanding SAML1?  The metadata I'm looking at suggests not at first blush.</pre>
    </blockquote>
    It seems that while going to my Shib  3 IdP ticket.iop.org uses
    SAML1. <br>
    I have in the log <br>
     2015-03-24 12:39:05,229 - DEBUG [PROTOCOL_MESSAGE:166] - <br>
    SAML 1 IdP-initiated request was:
    IdPInitiatedSSORequest{entityId=<a class="moz-txt-link-freetext" href="https://ticket.iop.org/shibboleth">https://ticket.iop.org/shibboleth</a>,
    acsURL=<a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML/POST">https://ticket.iop.org/Shibboleth.sso/SAML/POST</a>,
    relayState=cookie:534566a6, time=2015-03-24T11:39:04.000Z}<br>
    and then IdP produces &lt;saml1p:response&gt; and send it to <br>
    <br>
    I have the production IdP running simplesamlphp and there all works
    good. SAML tracer shows  that first &lt;samlp:AuthnRequest..&gt; is
    sent, then &lt;samlp:Response&gt; and the POST goes to SAML2
    endpoint<br>
    <small><a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML2/POST">https://ticket.iop.org/Shibboleth.sso/SAML2/POST</a></small><br>
    <br>
    <blockquote
      cite="mid:00ad01d06623$ad3ae130$07b0a390$@steadingsoftware.com"
      type="cite">
      <pre wrap="">

But then they also appear to be being doing something odd with discovery to do with per federation responses, and then end up with a Shibboleth (SAML1) query.

I've just tested a SAML1 sp against a V3 IdP (with attribute pull) and it did "what I expected" (show attribute screen and then release them), so it's not a simple bug.

More by way of straw-grasping, can you force the artefact profile and see what happens:

&lt;youtIdP&gt;/idp/profile/Shibboleth/SSO?shire=https%3A%2F%2Fticket.iop.org%2FShibboleth.sso%2FSAML%2FArtifact&amp;target=cookie%3A015f5922&amp;providerId=https%3A%2F%2Fticket.iop.org%2Fshibboleth

</pre>
    </blockquote>
    With this request I'm getting an error from
    <a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML/Artifact">https://ticket.iop.org/Shibboleth.sso/SAML/Artifact</a>...:<br>
    <h1><small><small>opensaml::BindingException</small></small></h1>
    <p>The system encountered an error at Tue Mar 24 11:18:49 2015
    </p>
    <p>To report this problem, please contact the site administrator at
      <a href="mailto:custserv@iop.org">custserv@iop.org</a>.
    </p>
    <p>Please include the following message in any email:</p>
    <p class="error">opensaml::BindingException at
      (<a class="moz-txt-link-freetext" href="https://ticket.iop.org/Shibboleth.sso/SAML/Artifact">https://ticket.iop.org/Shibboleth.sso/SAML/Artifact</a>)</p>
    <p>Unable to resolve artifact(s) into a SAML response.</p>
    <br>
    Maja<br>
    <blockquote
      cite="mid:00ad01d06623$ad3ae130$07b0a390$@steadingsoftware.com"
      type="cite">
      <pre wrap="">



</pre>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
Maja Gorecka-Wolniewicz          <a class="moz-txt-link-abbreviated" href="mailto:mgw@umk.pl">mgw@umk.pl</a>
Uczelniane Centrum               Information &amp; Communication
Informatyczne                    Technology Centre
Uniwersytet Mikolaja Kopernika   Nicolaus Copernicus University
Coll. Maximum, pl. Rapackiego 1, 87-100 Torun, Poland
tel.: +48 56-611-27-40 fax: +48 56-622-18-50 tel. kom.: +48-693032574</pre>
  </body>
</html>