<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hi all, <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I’m setting up shib in our production environment and have gotten so far as to the SP authenticating against the idP, but it bombs on the redirecting back to the resource.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I’ve already gone through this practice with a dev idP and that works perfectly.
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Digging through the logs I think this is the issue (see below), but I’m not sure if this translates into adding new attributes, or if the metadata for our prod idP is wrong, or something else.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.SSO.SAML2 [2]: SSO profile processing completed successfully<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.SSO.SAML2 [2]: extracting pushed attributes...<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.AttributeExtractor.XML [2]: unable to extract attributes, unknown XML object type: saml2p:Response<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.AttributeExtractor.XML [2]: skipping unmapped NameID with format (urn:oasis:names:tc:SAML:2.0:nameid-format:transient)<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.AttributeExtractor.XML [2]: unable to extract attributes, unknown XML object type: saml2:AuthnStatement<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.AttributeDecoder.Scoped [2]: decoding ScopedAttribute (affiliation) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.9) with 4 value(s)<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 INFO Shibboleth.AttributeExtractor.XML [2]: skipping unmapped SAML 2.0 Attribute with Name: urn:oid:2.5.4.3<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.AttributeDecoder.Scoped [2]: decoding ScopedAttribute (eppn) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.6) with 1 value(s)<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.AttributeDecoder.NameID [2]: decoding NameIDAttribute (persistent-id) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.10) with 1 value(s)<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.AttributeDecoder.NameID [2]: decoding saml2:NameID child element of AttributeValue<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 WARN Shibboleth.AttributeFilter.Dummy [2]: filtering out all attributes<o:p></o:p></p>
<p class="MsoNormal">2018-05-09 11:20:04 DEBUG Shibboleth.SSO.SAML2 [2]: resolving attributes...<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Can anyone offer some advice? <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks, <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">-Cascade <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>