<div dir="ltr"><div>In your isMemberOf you need to include the account number <br><br>cn=AWS-role,ou=accountid,ou=aws,ou=app,ou=nyu,ou=Groups,o= ....<br><br></div>and then<br><div><div><div class="gmail_extra"><br></div><div class="gmail_extra"> <AttributeDefinition id="awsRoles" xsi:type="Mapped" sourceAttributeID="isMemberOf"><br> <Dependency ref="NYU_LDAP" /><br> <AttributeEncoder xsi:type="SAML2String"<br> name="<a href="https://aws.amazon.com/SAML/Attributes/Role">https://aws.amazon.com/SAML/Attributes/Role</a>" friendlyName="Role" /><br> <ValueMap><br> <ReturnValue>arn:aws:iam::$2:saml-provider/<a href="http://shibboleth.nyu.edu">shibboleth.nyu.edu</a>,arn:aws:iam::$2:role/SSO-$1<br> </ReturnValue><br> <SourceValue>^cn=AWS-([^,]*),ou=(\d+),ou=aws,ou=app,ou=nyu,ou=Groups,.+</SourceValue><br> </ValueMap><br> </AttributeDefinition><br></div><div class="gmail_extra"><br></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Oct 4, 2017 at 11:51 AM, Jason Rotunno <span dir="ltr"><<a href="mailto:jrotunno@swarthmore.edu" target="_blank">jrotunno@swarthmore.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div>Hi,</div><div><br></div><div>I've integrated our AWS account with our Shib 3.3.1 instance for SSO access. The awsRoles attribute, which is required by AWS, is defined in attribute-resolver.xml as follows (111111111111 is the AWS account number):</div><div><br></div><div> <resolver:AttributeDefinition id="awsRoles" xsi:type="ad:Mapped" sourceAttributeID="memberOf"></div><div> <resolver:Dependency ref="myLDAP"/></div><div> <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="<a href="https://aws.amazon.com/SAML/Attributes/Role" target="_blank">https://aws.amazon.com/<wbr>SAML/Attributes/Role</a>" friendlyName="Role" /></div><div> <ad:ValueMap></div><div> <ad:ReturnValue></div><div> arn:aws:iam::111111111111:<wbr>role/Dept-1,arn:aws:iam::<wbr>111111111111:saml-provider/<wbr>shib.tld</div><div> </ad:ReturnValue></div><div> <ad:SourceValue ignoreCase="true">.*CN=Dept-1.<wbr>*</ad:SourceValue></div><div> </ad:ValueMap></div><div> </resolver:<wbr>AttributeDefinition></div><div><br></div><div>If a user is in the Dept-1 AD group, browses to <a href="https://shib.tld/idp/profile/SAML2/Unsolicited/SSO?providerId=urn:amazon:webservices" target="_blank">https://shib.tld/idp/profile/<wbr>SAML2/Unsolicited/SSO?<wbr>providerId=urn:amazon:<wbr>webservices</a> and authenticates, the awsRole is populated with the value arn:aws:iam::111111111111:<wbr>role/Dept-1,arn:aws:iam::<wbr>111111111111:saml-provider/<wbr>shib.tld. It's pretty straightforward and works well.</div><div><br></div><div>We have some other AWS accounts that I'd like to integrate with Shib as well, and I'm trying to figure out how to populate the awsRoles attribute with different account numbers based on which AWS account is being accessed.</div><div><br></div><div>For example, if a user authenticates at <a href="https://shib.tld/idp/profile/SAML2/Unsolicited/SSO?providerId=urn:amazon:webservices" target="_blank">https://shib.tld/idp/profile/<wbr>SAML2/Unsolicited/SSO?<wbr>providerId=urn:amazon:<wbr>webservices</a> (and is in the Dept-1 AD group), the awsRole value would be arn:aws:iam::111111111111:<wbr>role/Dept-1,arn:aws:iam::<wbr>111111111111:saml-provider/<wbr>shib.tld.</div><div><br></div><div>If the same user instead authenticates at <a href="https://shib.tld/idp/profile/SAML2/Unsolicited/SSO?providerId=urn:amazon:webservices:test" target="_blank">https://shib.tld/idp/profile/<wbr>SAML2/Unsolicited/SSO?<wbr>providerId=urn:amazon:<wbr>webservices:test</a>, the awsRole value would be arn:aws:iam::222222222222:<wbr>role/Dept-1,arn:aws:iam::<wbr>222222222222:saml-provider/<wbr>shib.tld.</div><div><br></div><div>Any suggestions on how I might do this? Or perhaps there's a better approach? I did find <a href="https://gist.github.com/zircote/488b1d8096c9d888e5ea" target="_blank">https://gist.github.com/<wbr>zircote/488b1d8096c9d888e5ea</a>, but that sets the account number based on AD membership. That wouldn't work for us since some users will need access to more than one AWS account.</div><div><br></div><div>Thanks,</div><div>Jason</div><span class="gmail-HOEnZb"><font color="#888888"><div><br></div>-- <br><div class="gmail-m_327947780815150093gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
<a href="tel:(610)%20328-8505" value="+16103288505" target="_blank">610.328.8505</a><br></pre><pre cols="72">Think BEFORE You Click!! Emails from Swarthmore College ITS won't be in your
Quarantine or Spam folder. We won't threaten you either! If you
receive any phishing emails, please forward them to <a href="mailto:phishing@swarthmore.edu" target="_blank">phishing@swarthmore.edu</a>.<br></pre></div></div></div></div></div>
</font></span></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><font size="2"><span title="yy27" style="padding:0px;border-width:0px;border-style:none;border-color:currentcolor;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px"><span style="padding:0px;border-width:0px;border-style:none;border-color:currentcolor;list-style-type:none">Yavor Yanakiev</span> </span><br style="padding:0px;border-width:0px;border-style:none;border-color:currentcolor;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px"><span style="padding:0px;border-width:0px;border-style:none;border-color:currentcolor;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px">Systems Developer for Identity Services</span></font><br><div>212-992-7585<br></div></div></div>
</div></div></div></div>