<div dir="ltr">In NetPartner Manager, on the Login tab, is the "Students login using" set to either the Alternate ID or Web ID? We use email1 because we are sending an email as a NameID (using format unspecified - of course!).<div><br></div><div>Don't suppose there are any clues in the NPStudent.log...</div><div><br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr">On Mon, May 14, 2018 at 4:07 PM Daudt, Carl <<a href="mailto:crdaudt@taylor.edu" target="_blank">crdaudt@taylor.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="m_-733738105905372740m_-3751945397746554016WordSection1">
<p class="MsoNormal">Uggh, I think I am close, but am still getting the same error from NetPartner:  “Your login failed. We could not validate your User Name.”<u></u><u></u></p>
<p class="MsoNormal">Any new ideas?<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Here is a recap:  Here is what I have for Shib:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Your assistance is greatly appreciated!!<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">--- metadata ---<u></u><u></u></p>
<p class="MsoNormal"><EntityDescriptor entityID="NetPartner"<u></u><u></u></p>
<p class="MsoNormal">                xmlns="urn:oasis:names:tc:SAML:2.0:metadata"><u></u><u></u></p>
<p class="MsoNormal">        <SPSSODescriptor<u></u><u></u></p>
<p class="MsoNormal">            protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol<u></u><u></u></p>
<p class="MsoNormal">            urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"><u></u><u></u></p>
<p class="MsoNormal">        <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat><u></u><u></u></p>
<p class="MsoNormal">        <AssertionConsumerService index="1"<u></u><u></u></p>
<p class="MsoNormal">            Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<u></u><u></u></p>
<p class="MsoNormal">                    Location="<a href="https://myfapprd.taylor.edu/NetPartnerStudent/Logon.aspx" target="_blank">https://myfapprd.taylor.edu/NetPartnerStudent/Logon.aspx</a>"/><u></u><u></u></p>
<p class="MsoNormal">        </SPSSODescriptor><u></u><u></u></p>
<p class="MsoNormal"></EntityDescriptor><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">--- attribute-resolver.xml ---<u></u><u></u></p>
<p class="MsoNormal">    <resolver:AttributeDefinition xsi:type="Simple" id="netPartnerStudentID" xmlns="urn:mace:shibboleth:2.0:resolver:ad" sourceAttributeID="SpriIdAlias"><u></u><u></u></p>
<p class="MsoNormal">        <resolver:Dependency ref="mySIS2" /><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="SAML1StringNameIdentifier" xmlns="urn:mace:shibboleth:2.0:attribute:encoder" nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" /><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="SAML2StringNameID" xmlns="urn:mace:shibboleth:2.0:attribute:encoder" nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified" /><u></u><u></u></p>
<p class="MsoNormal">    </resolver:AttributeDefinition><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">    <resolver:AttributeDefinition xsi:type="ad:TransientId" id="transientId"><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="enc:SAML1StringNameIdentifier" nameFormat="urn:mace:shibboleth:1.0:nameIdentifier" /><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID" nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" /><u></u><u></u></p>
<p class="MsoNormal">    </resolver:AttributeDefinition><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">--- attribute-filter.xml ---<u></u><u></u></p>
<p class="MsoNormal">    <AttributeFilterPolicy id="releaseForNetPartnerSP"><u></u><u></u></p>
<p class="MsoNormal">        <PolicyRequirementRule xsi:type="Requester" value="NetPartner" /><u></u><u></u></p>
<p class="MsoNormal">        <AttributeRule attributeID="netPartnerStudentID"><u></u><u></u></p>
<p class="MsoNormal">            <PermitValueRule xsi:type="ANY"/><u></u><u></u></p>
<p class="MsoNormal">        </AttributeRule><u></u><u></u></p>
<p class="MsoNormal">    </AttributeFilterPolicy><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">--- relying-party.xml ---<u></u><u></u></p>
<p class="MsoNormal">        <bean parent="RelyingPartyByName" c:relyingPartyIds="NetPartner"><u></u><u></u></p>
<p class="MsoNormal">            <property name="profileConfigurations"><u></u><u></u></p>
<p class="MsoNormal">                <list><u></u><u></u></p>
<p class="MsoNormal">                    <bean parent="Shibboleth.SSO" p:securityConfiguration-ref="SHA1SecurityConfig" /><u></u><u></u></p>
<p class="MsoNormal">                    <bean parent="SAML1.AttributeQuery" p:securityConfiguration-ref="SHA1SecurityConfig" /><u></u><u></u></p>
<p class="MsoNormal">                    <bean parent="SAML1.ArtifactResolution" p:securityConfiguration-ref="SHA1SecurityConfig" /><u></u><u></u></p>
<p class="MsoNormal">                    <bean parent="SAML2.ECP" p:securityConfiguration-ref="SHA1SecurityConfig" /><u></u><u></u></p>
<p class="MsoNormal">                    <bean parent="SAML2.Logout" p:securityConfiguration-ref="SHA1SecurityConfig" /><u></u><u></u></p>
<p class="MsoNormal">                    <bean parent="SAML2.AttributeQuery" p:securityConfiguration-ref="SHA1SecurityConfig" /><u></u><u></u></p>
<p class="MsoNormal">                    <bean parent="SAML2.ArtifactResolution" p:securityConfiguration-ref="SHA1SecurityConfig" /><u></u><u></u></p>
<p class="MsoNormal">                                    <bean parent="SAML2.SSO"<u></u><u></u></p>
<p class="MsoNormal">                                                p:encryptAssertions="false"<u></u><u></u></p>
<p class="MsoNormal">                                                p:securityConfiguration-ref="SHA1SecurityConfig"<u></u><u></u></p>
<p class="MsoNormal">                                     /><u></u><u></u></p>
<p class="MsoNormal">                </list><u></u><u></u></p>
<p class="MsoNormal">            </property><u></u><u></u></p>
<p class="MsoNormal">        </bean><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">--- saml-nameid.xml ---<u></u><u></u></p>
<p class="MsoNormal">                <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<u></u><u></u></p>
<p class="MsoNormal">                                p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"<u></u><u></u></p>
<p class="MsoNormal">                                p:attributeSourceIds="#{ {'netPartnerStudentID'} }"<u></u><u></u></p>
<p class="MsoNormal">                ><u></u><u></u></p>
<p class="MsoNormal">                                <property name="activationCondition"><u></u><u></u></p>
<p class="MsoNormal">                                                <bean parent="shibboleth.Conditions.RelyingPartyId"><u></u><u></u></p>
<p class="MsoNormal">                                                                <constructor-arg name="candidates"><u></u><u></u></p>
<p class="MsoNormal">                                                                                <list><u></u><u></u></p>
<p class="MsoNormal">                                                                                                <value>NetPartner</value><u></u><u></u></p>
<p class="MsoNormal">                                                                                </list><u></u><u></u></p>
<p class="MsoNormal">                                                                </constructor-arg><u></u><u></u></p>
<p class="MsoNormal">                                                </bean><u></u><u></u></p>
<p class="MsoNormal">                                </property><u></u><u></u></p>
<p class="MsoNormal">                </bean><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">The Shibboleth idp-process.log file shows (with debug turned on) that the attribute netPartnerStudentID has a value of @12345678 (numerical value reported here is modified for security), and is released to NetPartner.<u></u><u></u></p>
<p class="MsoNormal">In NetPartner, the same value is set for both the Alternate ID and Web ID for a test student to @12345678.  When NetPartner is configured for regular login, I can log in for that user.  But when I set NetPartner for SAML Single Sign on,
 I get the error above.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><b><span style="font-family:"Gill Sans MT",sans-serif;color:#1f497d">Carl R. Daudt</span></b><span style="color:#1f497d"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1f497d">Enterprise Applications Systems Analyst, Information Technology</span><span style="color:#1f497d"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1f497d">Taylor University
<br>
236 W. Reade Avenue <br>
Upland, IN  46989 <br>
Office:  765-998-5313</span><span style="color:#1f497d"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif;color:#1f497d"><a href="mailto:crdaudt@taylor.edu" target="_blank"><span style="color:blue">crdaudt@taylor.edu</span></a></span><span style="font-size:10.0pt;font-family:"Gill Sans MT",sans-serif"><u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<br>
<br>
<font face="Gill Sans Regular, Gill Sans MT, Trebuchet MS, Helvetica" color="888888" size="2">The information in this communication is intended solely for the individual or entity to whom it is addressed. It may contain confidential or legally privileged information.
 If you are not the intended recipient, any disclosure, copying, distribution or reliance on the contents of this information is strictly prohibited, and may be unlawful. If you have received this communication in error, please notify us immediately by responding
 to the sender of this email, and then delete it from your system. Taylor University is not liable for the inaccurate or improper transmission of the information contained in this communication or for any delay in its receipt.</font>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="m_-733738105905372740gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><b>Tony Skalski</b></div><div dir="ltr">System Administrator | IT</div><div dir="ltr"><img src="https://docs.google.com/uc?export=download&id=0B8pehFb2jk1VTlJUMXNxQzlUZ0k&revid=0B8pehFb2jk1VR0ZGVzBjRksvU1NMQUdwSzNIa05Ea08ydjFFPQ" width="200" height="77"><br></div><div dir="ltr"><b>Office: </b><a>507-786-3227</a></div><div dir="ltr">1510 St. Olaf Avenue Northfield, MN 55057</div><div dir="ltr"><a href="http://stolaf.edu" target="_blank">stolaf.edu</a></div><div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>