<div dir="ltr">Doug,<div><br></div><div>Ruling out more of the potentially obvious, are you sure there is effective protection of the resource not seeing variables by Shibboleth in the first place, and is the REMOTE_USER you're seeing being populated by Shibboleth?  Attributes aren't globally exported, but are rather provided only to protected locations.</div><div><br></div><div>Take care,</div><div>Nate.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Nov 9, 2018 at 2:56 PM, Doug Pham <span dir="ltr"><<a href="mailto:phamx039@umn.edu" target="_blank">phamx039@umn.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">I did see this part but iterating through the server variables, nothing showed up.  I am hoping there is something simple I missed in the shibboleth2.xml file.<div><h3 id="m_8136268635885411235gmail-AttributeAccess-ServerVariables" style="margin:30px 0px 0px;padding:0px;color:rgb(0,0,0);font-size:16px;line-height:1.5;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif">Server Variables</h3><div class="m_8136268635885411235gmail-confluence-information-macro m_8136268635885411235gmail-confluence-information-macro-information m_8136268635885411235gmail-conf-macro m_8136268635885411235gmail-output-block" style="margin:10px 0px 1em;padding:10px 10px 10px 36px;background:rgb(252,252,252);border:1px solid rgb(170,184,198);border-radius:5px;color:rgb(51,51,51);min-height:20px;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px"><p class="m_8136268635885411235gmail-title" style="margin:0px;padding:0px;font-weight:bold">Always use Server Variables</p><span class="m_8136268635885411235gmail-aui-icon m_8136268635885411235gmail-aui-icon-small m_8136268635885411235gmail-aui-iconfont-info m_8136268635885411235gmail-confluence-information-macro-icon" style="background-repeat:no-repeat;background-position:0px 0px;border:none;display:block;height:16px;margin:0px 5px 0px 0px;padding:0px;vertical-align:text-bottom;width:16px;line-height:20px;color:rgb(74,103,133)"></span><div class="m_8136268635885411235gmail-confluence-information-macro-body" style="margin:0px;padding:0px"><p style="margin:0px;padding:0px"><span style="color:rgb(112,112,112)">Currently, the SP supports the use of server variables on all versions of <a href="https://wiki.shibboleth.net/confluence/display/SP3/Apache" style="color:rgb(50,96,186);text-decoration-line:none" target="_blank">Apache</a> and <a href="https://wiki.shibboleth.net/confluence/display/SP3/ISAPI" style="color:rgb(50,96,186);text-decoration-line:none" target="_blank">IIS</a> versions greater than 7. You should </span><strong>always</strong><span style="color:rgb(112,112,112)"> use this mechanism with web servers that support it.</span></p></div></div><br class="m_8136268635885411235gmail-Apple-interchange-newline"></div></div><div class="HOEnZb"><div class="h5"><br><div class="gmail_quote"><div dir="ltr">On Thu, Nov 8, 2018 at 7:09 PM Steven Teixeira <<a href="mailto:steixeira@csustan.edu" target="_blank">steixeira@csustan.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">From <a href="https://wiki.shibboleth.net/confluence/display/SP3/IIS" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/display/SP3/IIS</a> in the "New Version in V3 of the SP" section:<br>
<br>
        By default, it passes values to application using Server Variables rather than HTTP Headers.<br>
<br>
Did you upgrade from v2 on the same server or is this a new installation?  If this was an upgrade have you upgraded from the old plugin to take advantage of the new functionality?<br>
<br>
<a href="https://wiki.shibboleth.net/confluence/display/SP3/Upgrading+Older+ISAPI+Configuration" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/display/SP3/<wbr>Upgrading+Older+ISAPI+<wbr>Configuration</a><br>
<br>
Steven Teixeira<br>
<br>
<br>
<br>
----IF CLASSIFICATION START----<br>
<br>
----IF CLASSIFICATION END----<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.<wbr>net</a><br>
</blockquote></div><br clear="all"><div><br></div></div></div><div class="HOEnZb"><div class="h5">-- <br><div dir="ltr" class="m_8136268635885411235gmail_signature" data-smartmail="gmail_signature"><div dir="ltr">Doug Pham<div>Senior Programmer/Analyst<br><div><div>Housing & Residential Life</div></div></div><div>612-625-1377</div></div></div>
</div></div><br>-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>