<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; font-family: Calibri, sans-serif; font-size: 14px; color: rgb(0, 0, 0);">
<div>
<div>
<div>Thanks for the replies! Please look at the new files and let me know if this configuration looks correct. Obviously, I need to pass mail, givenName, sn, and sAMAccountName. Sorry, if this is repetitive…I appreciate the help on this. </div>
<div><br>
</div>
<div><br>
</div>
<div>
<div><b>attribute-resolver.xml</b></div>
<div><resolver:AttributeDefinition id="mail" xsi:type="ad:Scoped" scope="%{idp.scope}" sourceAttributeID="mail"></div>
<div><br>
</div>
<div><resolver:Dependency ref="bhccldap" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:mail" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:0.9.2342.19200300.100.1.3" friendlyName="mail" /></div>
<div><br>
</div>
<div></resolver:AttributeDefinition></div>
<div><br>
</div>
<div><br>
</div>
<div><resolver:AttributeDefinition id="givenName" xsi:type="ad:Scoped" scope="%{idp.scope}" sourceAttributeID="givenName"></div>
<div><br>
</div>
<div><resolver:Dependency ref="bhccldap" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:givenName" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:2.5.4.42" friendlyName="givenName" /></div>
<div><br>
</div>
<div></resolver:AttributeDefinition></div>
<div><br>
</div>
<div><br>
</div>
<div><resolver:AttributeDefinition id="sn" xsi:type="ad:Scoped" scope="%{idp.scope}" sourceAttributeID="sn"></div>
<div><br>
</div>
<div><resolver:Dependency ref="bhccldap" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML1ScopedString" name="urn:mace:dir:attribute-def:sn" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML2ScopedString" name="urn:oid:2.5.4.4" friendlyName="sn" /></div>
<div><br>
</div>
<div></resolver:AttributeDefinition></div>
<div><br>
</div>
<div><br>
</div>
<div><resolver:AttributeDefinition xsi:type="ad:Simple" id="sAMAccountName" sourceAttributeID="sAMAccountName" xmlns="urn:mace:shibboleth:2.0:resolver:ad"></div>
<div><br>
</div>
<div><resolver:Dependency ref="bhccldap" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML1String" name="urn:mace:dir:attribute-def:sAMAccountName" /></div>
<div><br>
</div>
<div><resolver:AttributeEncoder xsi:type="enc:SAML2String" name="urn:oid:1.2.840.113556.1.4.221" friendlyName="sAMAccountName" /></div>
<div><br>
</div>
<div></resolver:AttributeDefinition></div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><b>attribute-filter.xml</b></div>
<div><br>
</div>
<div><afp:AttributeFilterPolicyGroup id="ShibbolethFilterPolicy"</div>
<div>xmlns:afp="urn:mace:shibboleth:2.0:afp" xmlns:basic="urn:mace:shibboleth:2.0:afp:mf:basic"
</div>
<div>xmlns:saml="urn:mace:shibboleth:2.0:afp:mf:saml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
</div>
<div>xsi:schemaLocation="urn:mace:shibboleth:2.0:afp classpath:/schema/shibboleth-2.0-afp.xsd</div>
<div>urn:mace:shibboleth:2.0:afp:mf:basic classpath:/schema/shibboleth-2.0-afp-mf-basic.xsd</div>
<div>urn:mace:shibboleth:2.0:afp:mf:saml classpath:/schema/shibboleth-2.0-afp-mf-saml.xsd"></div>
<div><br>
</div>
<div><!-- Release mail, givenName,sn, and sAMaccountName --></div>
<div><afp:AttributeFilterPolicy id="releaseToAnyone"></div>
<div><afp:PolicyRequirementRule xsi:type="basic:ANY"/></div>
<div><br>
</div>
<div><afp:AttributeRule attributeID="mail"></div>
<div><afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div></afp:AttributeRule></div>
<div><br>
</div>
<div><afp:AttributeRule attributeID="givenName"></div>
<div><afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div></afp:AttributeRule></div>
<div></div>
<div><afp:AttributeRule attributeID="sn"></div>
<div><afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div></afp:AttributeRule></div>
<div><br>
</div>
<div><afp:AttributeRule attributeID="sAMAccountName"></div>
<div><afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div></afp:AttributeRule> </div>
<div></afp:AttributeFilterPolicy></div>
<div><br>
</div>
<div></afp:AttributeFilterPolicyGroup></div>
<div><br>
</div>
<div><br>
</div>
</div>
<div>
<div id="MAC_OUTLOOK_SIGNATURE">
<div><br>
</div>
</div>
</div>
</div>
</div>
<div><br>
</div>
<div>On 4/7/16, 12:31 PM, "users on behalf of Peter Schober" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of
<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:</div>
<div><br>
</div>
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>* Byron Sayres <<a href="mailto:bsayres@rcc.mass.edu">bsayres@rcc.mass.edu</a>> [2016-04-07 17:48]:</div>
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>they have only asserted one attribute (named</div>
<div>"urn:oid:1.3.6.1.4.1.5923.1.1.1.9"</div>
<div>(a.k.a. "eduPersonScopedAffiliation").  They are not releasing any</div>
<div>of the attributes they have requested us to map.  My first guess</div>
<div>would be there is an error  in their attribute release policy.</div>
</blockquote>
<div><br>
</div>
<div>First thing would be looking at your IDP logs (idp-audit.log) to find</div>
<div>out what atributes you actually released to that SP.</div>
<div>(I'm assuming that will only show eduPersonScopedAffiliation below.)</div>
<div><br>
</div>
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>The requested values to map are</div>
<div>x-r25-first-name = urn:oid:2.5.4.42</div>
<div>x-r25-family-name = urn:oid:2.5.4.4</div>
<div>x-r25-email-work = urn:oid:0.9.2342.19200300.100.1.3</div>
<div>x-r25-user = urn:oid:1.3.6.1.4.1.5923.1.1.1.6</div>
</blockquote>
<div><br>
</div>
<div>OK, givenName, sn, mail, ePPN.</div>
<div>But you don't release half of them in the config snipped you sent:</div>
<div><br>
</div>
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>Here is my attribute-filter.xml</div>
<div></div>
<div>attribute-filter.xml</div>
<div>         <afp:AttributeRule attributeID="mail"></div>
<div>             <afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div>         </afp:AttributeRule></div>
<div></div>
<div><afp:AttributeRule attributeID="givenName"></div>
<div>             <afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div>         </afp:AttributeRule></div>
<div><afp:AttributeRule attributeID="sn"></div>
<div>             <afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div>         </afp:AttributeRule></div>
<div><afp:AttributeRule attributeID="sAMAccountName"></div>
<div>             <afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div>         </afp:AttributeRule></div>
<div></div>
<div><afp:AttributeRule attributeID="eduPersonScopedAffiliation"></div>
<div>             <afp:PermitValueRule xsi:type="basic:ANY" /></div>
<div>         </afp:AttributeRule></div>
</blockquote>
<div><br>
</div>
<div>You release sAMAccountName instead of ePPN (which is only the source</div>
<div>attribute you populate ePPN from, so probably a copy/paste error from</div>
<div>your resolver configuration) and Nate already pointed out that "sn" !=</div>
<div>"surename".</div>
<div>(The attributeID values must match the id values from your resolver.)</div>
<div><br>
</div>
<div>If it's correct that the SP only recieves eduPersonScopedAffiliation</div>
<div>I'd also suggest that the above probably isn't active at all (reason</div>
<div>would be an incorrect PolicyRequirementRule, as implied above) and</div>
<div>that you release eduPersonScopedAffiliation to the SP from some other</div>
<div>overarching rule. (Possibly one that releases</div>
<div>eduPersonScopedAffiliation to anyone, or some such.)</div>
<div><br>
</div>
<div>We can't help with the PolicyRequirementRule as (a) you don't include</div>
<div>it, and (b) even if you did we don't know the correct name of the SP,</div>
<div>but that's where I'd look -- after making sure you know what you</div>
<div>actually released.</div>
<div>-peter</div>
<div>-- </div>
<div>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></div>
<div><br>
</div>
</blockquote>
</body>
</html>