<div dir="ltr"><div class="gmail_default" style="font-family:times new roman,serif">Looking at our config, the main difference I see is that we have signAssterions set to true.</div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><br><font face="times new roman, serif">Brian Moon</font><br><font face="times new roman, serif">Senior System Administrator</font><br><font face="times new roman, serif">Enterprise Systems</font><br><font face="times new roman, serif">Santa Clara University</font><br><font face="times new roman, serif">Office: 408.554.4830</font><br><a href="mailto:bmoon@scu.edu" style="font-family:'times new roman',serif" target="_blank">bmoon@scu.edu</a><br></div></div></div></div></div></div></div></div></div></div></div>
<br><div class="gmail_quote">On Mon, Jun 26, 2017 at 10:15 AM, Joshua Brodie <span dir="ltr"><<a href="mailto:josbrodie@gmail.com" target="_blank">josbrodie@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Canvas on V3 does not appear to be receiving attributes after successful auth (nameID is fine)-- all is well with the attribute-filter and attribute-resolver (over 300 integration successful).</div><div><br></div><div>The idp-process.log also concur that the attributes are not sent (nameID is received).<br></div><div><br></div><div>We think it could be relying-party.xml ----- have we missed anything here?<br></div><div><br></div><div><br></div><div><bean parent="RelyingPartyByName"<br> c:relyingPartyIds="#{{'<a href="http://example.instructure.com/saml2'%7D" target="_blank">http://<wbr>example.instructure.com/saml2'<wbr>}</a>}"><br> <property name="profileConfigurations"><br> <list><br> <bean parent="Shibboleth.SSO" /><br> <bean parent="SAML2.SSO" <br> p:encryptAssertions="false"<br> p:includeAttributeStatement="<wbr>false"<br> p:signAssertions="false"<br> p:encryptNameIDs="false"<br> p:nameIDFormatPrecedence="#{{'<wbr>urn:oasis:names:tc:SAML:2.0:<wbr>nameid-format:unspecified'}}" /><br> <ref bean="SAML2.Logout" /><br> </list><br> </property><br> </bean><br></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>