<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
One of our developer is working on an on-prem SP and has the
following he can not resolve:<br>
<br>
<tt>IdP configured and releases the correct 3 attributes in
SAML-tracer:</tt><tt><br>
</tt><tt>
</tt>
<div
style="mso-element:para-border-div;border:none;border-left:solid
windowtext 1.0pt;padding:0in 0in 0in
4.0pt;margin-left:.5in;margin-right:0in">
<tt><br>
</tt><tt><saml2:AttributeStatement></tt><tt><br>
</tt>
<tt> <saml2:Attribute FriendlyName="<b>cn</b>"
Name="urn:oid:2.5.4.3"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></tt><tt><br>
</tt>
<tt><saml2:AttributeValue
xmlns:xsi=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema-instance">"http://www.w3.org/2001/XMLSchema-instance"</a>
xsi:type="xsd:string"><b>D</b><b>emoID</b></saml2:AttributeValue></tt><tt><br>
</tt>
<tt></tt><tt></saml2:Attribute></tt><tt><br>
</tt>
<tt></tt><tt><saml2:Attribute FriendlyName="<b>acmeGroups</b>"
Name="acmeGroups"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></tt><tt><br>
</tt> <tt><saml2:AttributeValue
xmlns:xsi=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema-instance">"http://www.w3.org/2001/XMLSchema-instance"</a>
xsi:type="xsd:string"><b>acme-RO</b></saml2:AttributeValue></tt><tt><br>
</tt> <tt><saml2:AttributeValue
xmlns:xsi=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema-instance">"http://www.w3.org/2001/XMLSchema-instance"</a>
xsi:type="xsd:string"><b>acme-RW</b></saml2:AttributeValue></tt><tt><br>
</tt>
<tt> . . . </tt><tt><br>
</tt>
<tt></saml2:Attribute></tt><tt><br>
</tt>
<tt><saml2:Attribute FriendlyName="<b>sn</b>"
Name="urn:oid:2.5.4.4"
NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></tt><tt><br>
</tt> <tt><saml2:AttributeValue
xmlns:xsi=<a class="moz-txt-link-rfc2396E" href="http://www.w3.org/2001/XMLSchema-instance">"http://www.w3.org/2001/XMLSchema-instance"</a>
xsi:type="xsd:string"><b>Demo</b></saml2:AttributeValue></tt><tt><br>
</tt>
<tt></saml2:Attribute></tt><tt><br>
</tt>
<tt></saml2:AttributeStatement></tt><tt><br>
</tt>
</div>
<tt>
</tt><tt><br>
</tt><tt><br>
</tt><tt>The SP attribute-map.xml contains the following:</tt><tt><br>
</tt><tt>
</tt>
<div
style="mso-element:para-border-div;border:none;border-left:solid
windowtext 1.0pt;padding:0in 0in 0in
4.0pt;margin-left:.5in;margin-right:0in">
<tt><br>
</tt><tt><Attribute name="urn:oid:2.5.4.3" id="<b>cn</b>"/></tt><tt><br>
</tt>
<tt><Attribute name="urn:oid:2.5.4.4" id="<b>sn</b>"/></tt><tt><br>
</tt>
<tt><Attribute name="acmeGroups" id="<b>acmeGroups</b>"
nameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"/></tt><tt><br>
</tt>
</div>
<tt>
</tt><tt><br>
</tt><tt><br>
</tt><tt>The SP’s shibd.log has the following when an auth is
successful:</tt><tt><br>
</tt><tt>
</tt><tt></tt><tt><br>
</tt><tt>
</tt>
<div
style="mso-element:para-border-div;border:none;border-left:solid
windowtext 1.0pt;padding:0in 0in 0in
4.0pt;margin-left:.5in;margin-right:0in">
<tt><br>
</tt><tt>2020-01-23 16:13:40 INFO
Shibboleth.AttributeExtractor.XML [136] [default]: skipping
unmapped SAML 2.0 Attribute with Name: <b>acmeGroups</b></tt><tt><br>
</tt>
<tt>2020-01-23 16:13:40 INFO Shibboleth.AttributeExtractor.XML
[136] [default]: skipping unmapped SAML 2.0 Attribute with Name:
urn:oid:2.5.4.4</tt><tt><br>
</tt>
<tt>2020-01-23 16:13:40 INFO Shibboleth.SessionCache [136]
[default]: new session created: ID
(_047fedc8ff4c37dc200fdc95d313d02f) . . .</tt><tt><br>
</tt>
</div>
<tt>
</tt><tt><br>
</tt><tt> </tt><tt><br>
</tt><tt>
Suggestions?<br>
<br>
</tt><br>
<br>
<br>
Thanks,<br>
Don<br>
<tt></tt>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>