<div dir="ltr">Hi <span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px">Stephen, peter and Rob</span><div><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></span></div><div><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px">Thanks for your reply.</span></div><div><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></span></div><div><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px">As per your suggection I have modified my </span><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px">attribute-resolver.xml file with bellow changes.</span></div><div><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></span></div><div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"> <AttributeDefinition xsi:type="Simple" id="realm" sourceAttributeID="realmval"></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"> <Dependency ref="realmRef" /></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"> <AttributeEncoder xsi:type="SAML1String" name="urn:mace:dir:attribute-def:realm" encodeType="false" /></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"> <AttributeEncoder xsi:type="SAML1String" name="urn:unsolicited:realm" friendlyName="realm" </span></font><span style="font-size:14.6667px;color:rgb(31,73,125);font-family:Calibri,sans-serif">encodeType="false" /></span></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"> </AttributeDefinition></span></font></div><div style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></div></div><div><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></span></div><div><div><DataConnector id="realmRef" xsi:type="Static" ></div><div> <Attribute id="realmval"></div><div> <Value>XYZ</Value></div><div> </Attribute></div></div><div><br></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"> </DataConnector></span></font><br></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px">But getting bellow error:</span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><div>2017-11-27 15:42:50,130 - ERROR [net.shibboleth.utilities.java.support.service.AbstractReloadableService:181] - Service 'shibboleth.AttributeResolverService': Initial load failed</div><div>net.shibboleth.utilities.java.support.service.ServiceException: org.springframework.beans.factory.xml.XmlBeanDefinitionStoreException: Line 38 in XML document from file [/opt/shibboleth-idp/conf/attribute-resolver-full.xml] is invalid; nested exception is org.xml.sax.SAXParseException; lineNumber: 38; columnNumber: 125; cvc-complex-type.3.2.2: Attribute 'friendlyName' is not allowed to appear in element 'AttributeEncoder'.</div><div><span style="white-space:pre"> </span>at net.shibboleth.ext.spring.service.ReloadableSpringService.doReload(ReloadableSpringService.java:336)</div><div>Caused by: org.springframework.beans.factory.xml.XmlBeanDefinitionStoreException: Line 38 in XML document from file [/opt/shibboleth-idp/conf/attribute-resolver-full.xml] is invalid; nested exception is org.xml.sax.SAXParseException; lineNumber: 38; columnNumber: 125; cvc-complex-type.3.2.2: Attribute 'friendlyName' is not allowed to appear in element 'AttributeEncoder'.</div><div><span style="white-space:pre"> </span>at org.springframework.beans.factory.xml.XmlBeanDefinitionReader.doLoadBeanDefinitions(XmlBeanDefinitionReader.java:399)</div><div>Caused by: org.xml.sax.SAXParseException: cvc-complex-type.3.2.2: <span style="background-color:rgb(255,255,0)">Attribute 'friendlyName' is not allowed to appear in element 'AttributeEncoder'.</span></div><div><span style="white-space:pre"> </span>at com.sun.org.apache.xerces.internal.util.ErrorHandlerWrapper.createSAXParseException(ErrorHandlerWrapper.java:203)</div><div>2017-11-27 15:42:50,130 - INFO [net.shibboleth.utilities.java.support.service.AbstractReloadableService:183] - Service 'shibboleth.AttributeResolverService': Continuing to poll configuration</div></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px">It seems that <span style="background-color:rgb(255,255,0)">name="urn:unsolicited:oid:realm"</span> is not correct/supported by SAML. Can you please help..</span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px">Snahasish</span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></div><div><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Nov 24, 2017 at 8:28 PM, Losen, Stephen C. (scl) <span dir="ltr"><<a href="mailto:scl@virginia.edu" target="_blank">scl@virginia.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div class="m_433524120215156226WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">To create attributes with “constant” or “static” values, look at the Static DataConnector. You will also need to make an AttributeDefinition for the attribute,
and this will be a “Simple” AttributeDefinition whose source attribute ID is defined in your Static DataConnector. And the Dependency will be the ID that you give your Static DataConnector.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><a href="https://wiki.shibboleth.net/confluence/display/IDP30/StaticDataConnector" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/display/IDP30/<wbr>StaticDataConnector</a><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><a href="https://wiki.shibboleth.net/confluence/display/IDP30/SimpleAttributeDefinition" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/display/IDP30/<wbr>SimpleAttributeDefinition</a><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Both of these will go in your attribute-resolver.xml file.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Stephen C. Losen<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">ITS - Systems and Storage<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">University of Virginia<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><a href="mailto:scl@virginia.edu" target="_blank"><span style="color:#0563c1">scl@virginia.edu</span></a> <a href="tel:(434)%20924-0640" value="+14349240640" target="_blank">434-924-0640</a><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users [mailto:<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@<wbr>shibboleth.net</a>]
<b>On Behalf Of </b>Santu Ghosh<br>
<b>Sent:</b> Friday, November 24, 2017 9:48 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject:</b> Re: Custom Attribute definitation<u></u><u></u></span></p><div><div class="h5">
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">Thanks Rod and Peter.<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Please my apologies for incomplete description.<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Sure I will keep in mind everything that you guys advised.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Thanks a lot.<u></u><u></u></p>
</div>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">On 24 Nov 2017 19:29, "Peter Schober" <<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>> wrote:<u></u><u></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal">* Santu Ghosh <<a href="mailto:mon.snahasish@gmail.com" target="_blank">mon.snahasish@gmail.com</a>> [2017-11-24 13:35]:<u></u><u></u></p>
<div>
<p class="MsoNormal">> To do this I have done in :<br>
><br>
> 1) attribute-resolver-full.xml<u></u><u></u></p>
</div>
<p class="MsoNormal">[...]<br>
> 2) attribute-resolver-ldap.xml<br>
<br>
None of these files are being used by the IDP by default, only<br>
attribute-resolver.xml is. The files you changed are merely examples<br>
(none of which you are following, so this is doubly useless).<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
> <AttributeDefinition xsi:type="Mapped" id="AREA"><br>
> <DefaultValue>USA</<wbr>DefaultValue><br>
> <ValueMap><br>
> <ReturnValue>USA</<wbr>ReturnValue><br>
> <SourceValue>USA</SourceValue><br>
> </ValueMap><u></u><u></u></p>
</div>
<p class="MsoNormal">What should mapping "USA" to "USA" accomplish?<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
> <AttributeDefinition xsi:type="Simple" id="AREA"><br>
> <DefaultValue>USA</<wbr>DefaultValue><br>
> <ValueMap><br>
> <ReturnValue>USA</<wbr>ReturnValue><br>
> <SourceValue>USA</SourceValue><br>
> </ValueMap><u></u><u></u></p>
</div>
<p class="MsoNormal">Obviously (?) a "Simple" attribute defintion is not a mapped attribute<br>
defintion and therefore cannot have a ValueMap.<br>
<br>
Nothing you're doing here makes any sense. If the existing<br>
documentation doesn't help you can ask specific questions about parts<br>
that are unclear.<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
> 3) ldap.properties<br>
><br>
> idp.attribute.resolver.LDAP.<wbr>returnAttributes = ou,uid,mail,surname,realm<u></u><u></u></p>
</div>
<p class="MsoNormal">The fact that you limit your default LDAP query to these attributes<br>
does not influence anything you're doing above. So this is immaterial<br>
unless you (later) want to generate something based on data from LDAP.<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
> 4) global.xml<br>
><br>
> <bean id="abc" class="java.lang.String"><br>
> <constructor-arg value="USA"/><br>
> </bean><br>
><br>
> <bean id="AREA" class="java.lang.String"><br>
> <constructor-arg value="USA"/><br>
> </bean><u></u><u></u></p>
</div>
<p class="MsoNormal">Could you point out the documentattion that suggests this?<br>
<br>
To answer the (not asked) question of how to produce an attribute with a<br>
static string as its value:<br>
<br>
* You define a "Static" data connector that has an Attribute as child<br>
element, with an id of your choice, and a Value child element with<br>
the static string value.<br>
<br>
* You define a "Simple" attribute with a uniquie id and the<br>
sourceAttributeID set to the id of the attribute you defined in the<br>
Data COnnector. Also add a Dependency element to reference the data<br>
connector.<br>
<br>
To release the attribute you write a filter rule referencing the id of<br>
the attribute you dedined, as always.<u></u><u></u></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
> but above setting ends with an error.<u></u><u></u></p>
</div>
<p class="MsoNormal">No doubt. But for the future you'll also need to be specific and<br>
provide the error message. We do not have access to your system (nor<br>
do we want to) and most of us here are not clairvoyant.<br>
<span style="color:#888888"><br>
-peter</span><u></u><u></u></p>
<div>
<p class="MsoNormal">--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.<wbr>net</a><u></u><u></u></p>
</div>
</blockquote>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div></div></div>
</div>
<br>--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div>Snahasish Ghosh<br><br></div></div></div>
</div>