<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Thanks Daniel,<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>    I did some testing and was able to bind and retrieve attributes using my service account.  To further test (since our shib install is still in testing) I set my user account as the bind account for the attribute resolver data connector.  I noticed it was using <a href="mailto:mrichter@coastal.edu">mrichter@coastal.edu</a> where the auth was using CN=mrichter, DC=coastal, DC=edu.    I changed it to match and restarted the shib service.  Still no luck.  Now the request lines are almost (but not exactly) the same.  I noticed the attribute resolver timeout is set to -1 while auth is 3000.  I assumed -1 was indefinite, but not sure now.  Not sure where this is set.  Below are the two lines form the log.  The first is the Auth bind which returns attributes.  The second is the resolver request which does not. Both use the same account to bind.  Any ideas,  I’m kind of spinning my wheels right now.  Thanks again for the assistance.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Auth:<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>2016-02-12 13:24:14,758 - DEBUG [org.ldaptive.BindOperation:138] - execute request=[org.ldaptive.BindRequest@2027945964::<span style='background:yellow;mso-highlight:yellow'>bindDn=CN=mrichter,DC=coastal, DC=edu</span>, saslConfig=null, controls=null] with connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection@2093912051::config=[org.ldaptive.ConnectionConfig@1438748210::ldapUrl=ldap://s12dc3.coastal.edu:389, connectTimeout=3000, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig@1009462361::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig@2c7b6eed, trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=true, connectionInitializer=null], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiStartTLSConnectionFactory@1847560384::metadata=[ldapUrl=ldap://s12dc3.coastal.edu:389, count=1], environment={com.sun.jndi.ldap.connect.timeout=3000, java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig@1493260940::operationExceptionResultCodes=[PROTOCOL_ERROR, SERVER_DOWN], properties={}, connectionStrategy=org.ldaptive.provider.ConnectionStrategies$DefaultConnectionStrategy@1b0dd58c, controlProcessor=org.ldaptive.provider.ControlProcessor@29074836, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED, SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null, hostnameVerifier=null], sslSocketFactory=[org.ldaptive.ssl.TLSSocketFactory@782295653::factory=sun.security.ssl.SSLSocketFactoryImpl@3ceb36f9, sslConfig=[org.ldaptive.ssl.SslConfig@1009462361::credentialConfig=net.shibboleth.idp.authn.impl.X509ResourceCredentialConfig@2c7b6eed, trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null]], hostnameVerifier=null], <a href="mailto:providerConnection=org.ldaptive.provider.jndi.JndiStartTLSConnection@6fedded2">providerConnection=org.ldaptive.provider.jndi.JndiStartTLSConnection@6fedded2</a>]<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><u><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Attrib resolve<o:p></o:p></span></u></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'> 2016-02-12 13:24:15,039 - DEBUG [org.ldaptive.BindOperation:138] - execute request=[org.ldaptive.BindRequest@1352120443::<span style='background:yellow;mso-highlight:yellow'>bindDn=CN=mrichter,DC=coastal,DC=edu</span>, saslConfig=null, controls=null] with connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection@1849386952::config=[org.ldaptive.ConnectionConfig@1638631856::ldapUrl=ldap://s12dc3.coastal.edu:389, connectTimeout=-1, responseTimeout=-1, sslConfig=[org.ldaptive.ssl.SslConfig@1417203230::credentialConfig=org.ldaptive.ssl.CredentialConfigFactory$2@5edc70ed, trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=true, connectionInitializer=[org.ldaptive.BindConnectionInitializer@1125614861::bindDn=CN=mrichter,DC=coastal,DC=edu, bindSaslConfig=null, bindControls=null]], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiStartTLSConnectionFactory@414315122::metadata=[ldapUrl=ldap://s12dc3.coastal.edu:389, count=1], environment={java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig@505635448::operationExceptionResultCodes=[PROTOCOL_ERROR, SERVER_DOWN], properties={}, connectionStrategy=org.ldaptive.provider.ConnectionStrategies$ActivePassiveConnectionStrategy@44fff386, controlProcessor=org.ldaptive.provider.ControlProcessor@1fc713c9, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED, SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null, hostnameVerifier=null], sslSocketFactory=[org.ldaptive.ssl.TLSSocketFactory@1882290876::factory=sun.security.ssl.SSLSocketFactoryImpl@1d8840a1, sslConfig=[org.ldaptive.ssl.SslConfig@1417203230::credentialConfig=org.ldaptive.ssl.CredentialConfigFactory$2@5edc70ed, trustManagers=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null]], hostnameVerifier=null], providerConnection=org.ldaptive.provider.jndi.JndiStartTLSConnection@28b871ff]<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><b><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span></b><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'> users [mailto:users-bounces@shibboleth.net] <b>On Behalf Of </b>Daniel Fisher<br><b>Sent:</b> Friday, February 12, 2016 12:22 PM<br><b>To:</b> Shib Users <users@shibboleth.net><br><b>Subject:</b> Re: Attributes not being release from AD<o:p></o:p></span></p><p class=MsoNormal><o:p> </o:p></p><div><div><div><p class=MsoNormal>On Fri, Feb 12, 2016 at 11:01 AM, Michael Richter <<a href="mailto:mrichter@coastal.edu" target="_blank">mrichter@coastal.edu</a>> wrote:<o:p></o:p></p><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in'><div><p>Druing Attribute resolution this is the result I get.  As you see, no attributes are returned even though I’m using the same search query .<o:p></o:p></p></div></blockquote><div><p class=MsoNormal>The attributes you're getting with the authentication flow are read as the authenticated user, not the bindDn credential used to resolve the DN. (Although you can change that behavior.)<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal> <o:p></o:p></p></div><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in'><div><p style='margin-left:.5in'>10:32:20,017 - DEBUG [org.ldaptive.SearchOperation:168] - execute response=[org.ldaptive.Response@1430069391::result=[org.ldaptive.SearchResult@-882078420::entries=[[dn=CN=mrichter,DC=coastal, DC=edu[],<o:p></o:p></p></div></blockquote><div><p class=MsoNormal>You found the entry, but got no attributes.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal> <o:p></o:p></p></div><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in'><div><p style='margin-left:.5in'>baseDn=DC=coastal, DC=edu, searchFilter=[org.ldaptive.SearchFilter@-523314116::filter<span style='background:yellow'>=(sAMAccountName=mrichter</span>), parameters={}], returnAttributes=[cn,sn,displayName,mail,sAMAccountName], searchScope=SUBTREE,<o:p></o:p></p></div></blockquote><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>You definitely requested some attributes.<o:p></o:p></p></div><div><p class=MsoNormal> <o:p></o:p></p></div><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in'><div><p style='margin-left:.5in'>bindDn=<a href="mailto:shibdir@coastal.edu" target="_blank">shibdir@coastal.edu</a>, bindSaslConfig=null, bindControls=null]],<o:p></o:p></p></div></blockquote><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Is this user authorized to read the requested attributes?<o:p></o:p></p></div><div><p class=MsoNormal>It's generally easier to test this stuff using a command line tool like ldapsearch rather than exercising the IDP.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><p class=MsoNormal>ldapsearch -H ldap://<a href="http://s12dc3.coastal.edu:389">s12dc3.coastal.edu:389</a> -Z -x \\<br>-b 'DC=coastal,DC=edu' \\<br>-D '<a href="mailto:shibdir@coastal.edu">shibdir@coastal.edu</a>' -W \\<br>'(sAMAccountName=mrichter)'<o:p></o:p></p><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>--Daniel Fisher<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div></div></div></div></div></body></html>