<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">Hugo,</p>
<p style="margin-top:0;margin-bottom:0"></p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">They're giving you the ability to specify the precise path to something in the assertion that you want to use for that purpose.  I've never seen that before.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">There will be no defaults for Shibboleth since it depends on what you send, but a best practice might be:</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Identifier</p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">/samlp:Response/saml:Assertion/saml:AttributeStatement/saml:Attribute[@Name="<span>urn:oid:1.3.6.1.4.1.5923.1.1.1.6</span>"]/saml:AttributeValue</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">(eduPersonPrincipalName on the wire)</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">Same session index</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">Email</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">/samlp:Response/saml:Assertion/saml:AttributeStatement/saml:Attribute[@Name="urn:oid:</span><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"><span>0.9.2342.19200300.100.1.3</span></span><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">"]/saml:AttributeValue</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">(ldap mail on the wire)</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"></p>
<p style="color: rgb(33, 33, 33); font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;">
First Name</p>
<p style="color: rgb(33, 33, 33); font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;">
<span style="font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">/samlp:Response/saml:Assertion/saml:AttributeStatement/saml:Attribute[@Name="urn:oid:</span><span style="font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">2.5.4.42</span><span style="font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">"]/saml:AttributeValue</span></p>
<p style="color: rgb(33, 33, 33); font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;">
<span style="font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">(givenName on the wire)</span></p>
</span>
<p></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"><br>
</span></p>
<p style="margin-top:0;margin-bottom:0"><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"></p>
<p style="font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;">
<span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">Last Name</span></p>
<p style="font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;">
<span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">/samlp:Response/saml:Assertion/saml:AttributeStatement/saml:Attribute[@Name="</span><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">urn:oid:2.5.4.4</span><span style="color: rgb(85, 85, 85); font-family: Roboto, sans-serif; font-size: 16px;"></span><span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">]/saml:AttributeValue</span></p>
<p style="font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;">
<span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;">(sn on the wire)</span></p>
<p style="font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 16px;">
<span style="color: rgb(33, 33, 33); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif, serif, EmojiFont; font-size: 15px;"></span></p>
</span>
<p></p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Hugo Slavia <hugoslavia101@gmail.com><br>
<b>Sent:</b> Thursday, January 4, 2018 9:32:17 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Igloo Software</font>
<div> </div>
</div>
<div>
<div dir="ltr">Thanks. That was helpful, I set it up for IDP-initiated SSO (the entityID is the home URL for the community).
<div><br>
</div>
<div>There are the following fields to fill in the Igloo SAML webform for the response...with the default values listed (changes depending on the IdP selected -- Shibboleth not listed).</div>
<div><br>
</div>
<div>What can be the values to insert for Shibboleth? I tried a number of combinations -- including changing to mail, givenName, sn -- but no dice. <br>
<div><br>
</div>
<div><span style="color:rgb(51,51,51); font-family:Helvetica,Arial,sans-serif; font-size:12px; font-weight:700">Identifier Path</span><br>
</div>
<div><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px">/samlp:Response/saml:Assertion/saml:Subject/saml:NameID</span></font><br>
</div>
<div><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px"><b><br>
</b></span></font></div>
<div><span style="color:rgb(51,51,51); font-family:Helvetica,Arial,sans-serif; font-size:12px; font-weight:700">Session Index Path</span><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px"><b><br>
</b></span></font></div>
<div><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px">/samlp:Response/saml:Assertion/saml:AuthnStatement</span></font><br>
</div>
<div><br>
</div>
<div><span style="color:rgb(51,51,51); font-family:Helvetica,Arial,sans-serif; font-size:12px; font-weight:700">Email Path</span><br>
</div>
<div>/samlp:Response/saml:Assertion/saml:AttributeStatement/saml:Attribute[@Name="Email"]/saml:AttributeValue<br>
</div>
</div>
<div><br>
</div>
<div><span style="color:rgb(51,51,51); font-family:Helvetica,Arial,sans-serif; font-size:12px; font-weight:700">First Name Path</span><br>
</div>
<div><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px">/samlp:Response/saml:Assertion/saml:AttributeStatement/saml:Attribute[@Name="FName"]/saml:AttributeValue</span></font><br>
</div>
<div><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px"><b><br>
</b></span></font></div>
<div><span style="color:rgb(51,51,51); font-family:Helvetica,Arial,sans-serif; font-size:12px; font-weight:700">Last Name Path</span><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px"><b><br>
</b></span></font></div>
<div><font color="#333333" face="Helvetica, Arial, sans-serif"><span style="font-size:12px">/samlp:Response/saml:Assertion/saml:AttributeStatement/saml:Attribute[@Name="LName"]/saml:AttributeValue</span></font><br>
</div>
</div>
<div class="x_gmail_extra"><br>
<div class="x_gmail_quote">On Thu, Jan 4, 2018 at 4:10 PM, Tom Scavo <span dir="ltr">
<<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br>
<blockquote class="x_gmail_quote" style="margin:0 0 0 .8ex; border-left:1px #ccc solid; padding-left:1ex">
<span class="">On Thu, Jan 4, 2018 at 5:38 PM, Hugo Slavia <<a href="mailto:hugoslavia101@gmail.com">hugoslavia101@gmail.com</a>> wrote:<br>
><br>
> Their instructions are at:<br>
> <a href="https://customercare.igloosoftware.com/support/knowledgebase/articles/sso_saml_authentication" rel="noreferrer" target="_blank">
https://customercare.<wbr>igloosoftware.com/support/<wbr>knowledgebase/articles/sso_<wbr>saml_authentication</a><br>
><br>
> But what do I enter on the IdP side of the equation for the metadata?<br>
<br>
</span>If the SP doesn't provide metadata, you'll have to provide it yourself.<br>
<span class=""><br>
> Can an IdP-initiated SSO occur without entry in the IdP metadata?<br>
<br>
</span>IdP-initiated, SP-initiated, it doesn't matter, the IdP needs metadata<br>
for every SP.<br>
<span class=""><br>
> What about how to<br>
> list which attributes for release?<br>
<br>
</span>The SP entityID is in the SP metadata. Presumably attribute release<br>
will be driven by the SP entityID.<br>
<span class="x_HOEnZb"><font color="#888888"><br>
Tom<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">
https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote>
</div>
<br>
</div>
</div>
</body>
</html>