<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Greetings!<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am experiencing a Shibboleth IdP configuration problem (mentioned in the<o:p></o:p></p>
<p class="MsoNormal">subject line) and would be grateful if someone on this mailing list could lend<o:p></o:p></p>
<p class="MsoNormal">some advice.  I still consider myself a beginner in Shibboleth administration,<o:p></o:p></p>
<p class="MsoNormal">so perhaps the root cause of this problem will be easy for you to diagnose.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">General background:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">  - My organization is simultaneously running a Shib v2 and Shib v3 IdP<o:p></o:p></p>
<p class="MsoNormal">  - We just recently spun up the Shib v3 IdP, and gave it a different hostname<o:p></o:p></p>
<p class="MsoNormal">    than the Shib v2 IdP; the entity IDs are the same<o:p></o:p></p>
<p class="MsoNormal">  - Our plan is to gradually transition SPs from using the v2 IdP to the v3 IdP<o:p></o:p></p>
<p class="MsoNormal">  - I do not have access to the v2 IdP, but I am still responsible for updating<o:p></o:p></p>
<p class="MsoNormal">    configuration files and directing its administration; a colleague of mine<o:p></o:p></p>
<p class="MsoNormal">    performs my requested actions<o:p></o:p></p>
<p class="MsoNormal">  - The v2 IdP is running on Tomcat; I think it is using Catalina as the web<o:p></o:p></p>
<p class="MsoNormal">    server, but it might be using IIS<o:p></o:p></p>
<p class="MsoNormal">  - I have access to the v3 IdP, which is running on Tomcat/Catalina/RHEL 7; I<o:p></o:p></p>
<p class="MsoNormal">    was the one who deployed the stack<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Problem-specific background:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">  - Within a short time frame, we need to establish SSO with a specific SP<o:p></o:p></p>
<p class="MsoNormal">  - Both our organization and this SP are members of the InCommon federation<o:p></o:p></p>
<p class="MsoNormal">  - Currently, InCommon has our v2 endpoints listed<o:p></o:p></p>
<p class="MsoNormal">  - We do not have time to push our new v3 endpoints to InCommon before this SP<o:p></o:p></p>
<p class="MsoNormal">    must be working<o:p></o:p></p>
<p class="MsoNormal">  - Even if we gave the SP standalone metadata for our v3 IdP (instead of going<o:p></o:p></p>
<p class="MsoNormal">    through InCommon), our v3 IdP is not well tested enough for management to<o:p></o:p></p>
<p class="MsoNormal">    feel comfortable enough to use it within our short timeframe<o:p></o:p></p>
<p class="MsoNormal">  - Due to the above, we are configuring our v2 IdP to work with this SP<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The problem:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">  - The SP is not receiving any attributes from our IdP<o:p></o:p></p>
<p class="MsoNormal">  - According to the SAML Tracer FF plugin, no `<AttributeStatement>' is sent<o:p></o:p></p>
<p class="MsoNormal">  - Technical personnel at the SP report that they are logging something like<o:p></o:p></p>
<p class="MsoNormal">    "not receiving eduPersonPrincipalName"<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">What we have done:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">  - Updated `attribute-filter.xml' to release attributes requested by the SP<o:p></o:p></p>
<p class="MsoNormal">  - Verified that the requested attributes exist in `attribute-resolver.xml'<o:p></o:p></p>
<p class="MsoNormal">  - Restarted Tomcat<o:p></o:p></p>
<p class="MsoNormal">  - Verified that our IdP provides correct SAML assertions in response to this<o:p></o:p></p>
<p class="MsoNormal">    SP (determined with SAML Tracer FF plugin)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Is there anything else I can do or any more information I can provide to aid<o:p></o:p></p>
<p class="MsoNormal">diagnostics?  Or does someone already know what's going on? :)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Sam<o:p></o:p></p>
</div>
</body>
</html>