<html><body><div id="edo-message"><div>This email is in a loop. I'm gettin multiple copies of it. Can someone fix this<br><br><pre id="edo-signature" style="font-family: 'Helvetica Neue','Helvetica',Helvetica,Arial,sans-serif;font:'-apple-system-body';">Sent from Mark Needleman's iPhone
</pre><br></div></div><div id="edo-original"><div><br><br><blockquote type="cite" style="margin:1ex 0 0 0;border-left:1px #ccc solid;padding-left:0.5ex;"><div>On May 8, 2016 at 6:20 PM, <<a href="mailto:chris@fdu.edu">Mr. Christopher Bland</a>> wrote:<br><br></div><div><pre>Hi All,
<br>
<br>I just installed a new v2.5.6 SP on RHEL6 to talk to a v2.4.2 IDP. The SP is setup like other SPs on campus. However I keep getting an infinite loop between the SP and the IDP. From what I can tell there is a breakdown processing the transient id. The IDP is receiving the request and sending a response. The shibd.log shows the following:
<br>
<br>2016-05-08 15:06:12 DEBUG Shibboleth.AttributeExtractor.XML [4]: unable to extract attributes, unknown XML object type: saml2p:Response
<br>2016-05-08 15:06:12 DEBUG Shibboleth.AttributeExtractor.XML [4]: skipping unmapped NameID with format (urn:oasis:names:tc:SAML:2.0:nameid-format:transient)
<br>2016-05-08 15:06:12 DEBUG Shibboleth.AttributeExtractor.XML [4]: unable to extract attributes, unknown XML object type: saml2:AuthnStatement
<br>
<br>The other attributes released in the response are decoded and processed fine
<br>
<br>2016-05-08 15:06:12 DEBUG Shibboleth.AttributeDecoder.String [4]: decoding SimpleAttribute (sn) from SAML 2 Attribute (urn:oid:2.5.4.4) with 1 value(s)
<br>2016-05-08 15:06:12 DEBUG Shibboleth.AttributeDecoder.String [4]: decoding SimpleAttribute (cn) from SAML 2 Attribute (urn:oid:2.5.4.3) with 1 value(s)
<br>2016-05-08 15:06:12 DEBUG Shibboleth.AttributeDecoder.String [4]: decoding SimpleAttribute (givenName) from SAML 2 Attribute (urn:oid:2.5.4.42) with 1 value(s)
<br>
<br>The transient id is defined as follows on the IDP
<br>
<br> <resolver:AttributeDefinition id="transientId" xsi:type="TransientId" xmlns="urn:mace:shibboleth:2.0:resolver:ad">
<br> <resolver:AttributeEncoder xsi:type="SAML1StringNameIdentifier" xmlns="urn:mace:shibboleth:2.0:attribute:encoder"
<br> nameFormat="urn:mace:shibboleth:1.0:nameIdentifier" />
<br>
<br> <resolver:AttributeEncoder xsi:type="SAML2StringNameID" xmlns="urn:mace:shibboleth:2.0:attribute:encoder"
<br> nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" />
<br>
<br> </resolver:AttributeDefinition>
<br>
<br>
<br> <resolver:PrincipalConnector xsi:type="Transient" xmlns="urn:mace:shibboleth:2.0:resolver:pc" id="shibTransient"
<br> nameIDFormat="urn:mace:shibboleth:1.0:nameIdentifier" />
<br>
<br> <resolver:PrincipalConnector xsi:type="Transient" xmlns="urn:mace:shibboleth:2.0:resolver:pc" id="saml1Unspec"
<br> nameIDFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" />
<br>
<br> <resolver:PrincipalConnector xsi:type="Transient" xmlns="urn:mace:shibboleth:2.0:resolver:pc" id="saml2Transient"
<br> nameIDFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" />
<br>
<br>
<br>I’ve gone through the attribute-map.xml file on this and other SPs and I don’t see historically where it was necessary to define the transient id.
<br>
<br>All thoughts and suggestions welcome.
<br>
<br>Thank you in advance,
<br>
<br>-Chris
<br>
<br>-- <br>To unsubscribe from this list send an email to <a dir="ltr" href="mailto:users-unsubscribe@shibboleth.net" x-apple-data-detectors="true" x-apple-data-detectors-type="link" x-apple-data-detectors-result="10">users-unsubscribe@shibboleth.net</a></pre></div></blockquote></div></div></body></html>