<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">Here's the on the wire stuff...</div><div dir="ltr"><br></div><div dir="ltr">DEBUG logs from the IdP side (pre-encoding):<div><div> <saml2:AttributeStatement></div><div> <saml2:Attribute FriendlyName="eduPersonScopedAffiliation"</div><div> Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></div><div> <saml2:AttributeValue><a href="mailto:Staff@hull-college.ac.uk">Staff@hull-college.ac.uk</a></saml2:AttributeValue></div><div> </saml2:Attribute></div><div> <saml2:Attribute FriendlyName="mail"</div><div> Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></div><div> <saml2:AttributeValue><a href="mailto:Dave.Perry@hull-college.ac.uk">Dave.Perry@hull-college.ac.uk</a></saml2:AttributeValue></div><div> </saml2:Attribute></div><div> <saml2:Attribute FriendlyName="eduPersonTargetedID"</div><div> Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></div><div> <saml2:AttributeValue></div><div> <saml2:NameID</div><div> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"</div><div> NameQualifier="<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>" SPNameQualifier="<a href="https://webservices.hull-college.ac.uk/shibboleth">https://webservices.hull-college.ac.uk/shibboleth</a>">evK+lWyNCbZEhTDyOqlqrAmpJNo=</saml2:NameID></div><div> </saml2:AttributeValue></div><div> </saml2:Attribute></div><div> <saml2:Attribute FriendlyName="eduPersonPrincipalName"</div><div> Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></div><div> <saml2:AttributeValue><a href="mailto:70012521@Hull-College.ac.uk">70012521@Hull-College.ac.uk</a></saml2:AttributeValue></div><div> </saml2:Attribute></div><div> </saml2:AttributeStatement></div><div><br></div></div><div>DEBUG logs from the SP side (shibd.log):</div><div><div>2019-05-15 10:32:04 DEBUG Shibboleth.SSO.SAML2 [1] [default]: extracting pushed attributes...</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeExtractor.XML [1] [default]: unable to extract attributes, unknown XML object type: saml2p:Response</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeExtractor.XML [1] [default]: skipping unmapped NameID with format (urn:oasis:names:tc:SAML:2.0:nameid-format:transient)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeExtractor.XML [1] [default]: unable to extract attributes, unknown XML object type: saml2:AuthnStatement</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeDecoder.Scoped [1] [default]: decoding ScopedAttribute (affiliation) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.9) with 1 value(s)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeDecoder.String [1] [default]: decoding SimpleAttribute (mail) from SAML 2 Attribute (urn:oid:0.9.2342.19200300.100.1.3) with 1 value(s)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeDecoder.NameID [1] [default]: decoding NameIDAttribute (persistent-id) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.10) with 1 value(s)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeDecoder.NameID [1] [default]: decoding saml2:NameID child element of AttributeValue</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeDecoder.Scoped [1] [default]: decoding ScopedAttribute (eppn) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.6) with 1 value(s)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeFilter [1] [default]: filtering 4 attribute(s) from (<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeFilter [1] [default]: applying filtering rule(s) for attribute (eppn) from (<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>)</div><div>2019-05-15 10:32:04 WARN Shibboleth.AttributeFilter [1] [default]: removed value at position (0) of attribute (eppn) from (<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeFilter [1] [default]: applying filtering rule(s) for attribute (persistent-id) from (<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeFilter [1] [default]: applying filtering rule(s) for attribute (mail) from (<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>)</div><div>2019-05-15 10:32:04 DEBUG Shibboleth.AttributeFilter [1] [default]: applying filtering rule(s) for attribute (affiliation) from (<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>)</div><div>2019-05-15 10:32:04 WARN Shibboleth.AttributeFilter [1] [default]: no values left, removing attribute (eppn) from (<a href="https://shibb.hull-college.ac.uk/idp/shibboleth">https://shibb.hull-college.ac.uk/idp/shibboleth</a>)</div></div><div><br></div><div>From the IdP Metadata:</div><div><shibmd:Scope regexp="false"><a href="http://Hull-College.ac.uk">Hull-College.ac.uk</a></shibmd:Scope><br></div><div><br></div><div><br></div></div></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, May 15, 2019 at 11:24 AM Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* HCUK eLearning <<a href="mailto:daveperryatwork@gmail.com" target="_blank">daveperryatwork@gmail.com</a>> [2019-05-15 11:37]:<br>
> The userPrincipalName comes from an AD attribute and includes the<br>
> domain/scope already. [...]<br>
> <br>
> I can't see how to define a scope as a parameter (I tried scope="@<br>
> <a href="http://hull-college.ac.uk" rel="noreferrer" target="_blank">hull-college.ac.uk</a>" as an attribute of the definition, to no avail).<br>
<br>
There's no need to do any of that. If the attribute comes "scoped"<br>
from LDAP and you put it into a "Prescoped" attribute definition<br>
you're done! There's nothing else needed, otherwise the docs would be<br>
mentioning it.<br>
<br>
If that doesn't help you fix this: Could you just post the data<br>
verbatim? What's the value, how does your IDP existing config look<br>
like? Alternatively: How does it look on the wire (IDP or SP debug<br>
log)? That way we can eliminate the IDP as the source of the problem.<br>
<br>
> A post I found via google led me to attribute-policy on the SP side, so I<br>
> modified the scope on on ScopedRules there to be @<a href="http://hull-college.ac.uk" rel="noreferrer" target="_blank">hull-college.ac.uk</a>, and<br>
> restarted the SP. But it still didn't work.<br>
<br>
You shouldn't need to do that, either. An IDP should only release<br>
attributes with scopes that its own metadata whilelists. I.e., the<br>
metadata the SP has about the IDP should contain all scopes the IDP<br>
intends to assert attributes in.<br>
<br>
So I think it comes down to the IDP asserting the wrong -- either<br>
factually wrong or simply not part of its published metadata, yet --<br>
scopes. An SP should not need to change its policies for any of this:<br>
Those are generic rules that help prevent impersonation by rogue IDPs<br>
and should always remain in place. <br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>