<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div style=""><font color="#1f497d" face="Verdana, sans-serif" data-ogsc="" style=""><span style="font-size:14.6667px"><b>Pasquale Tedesco</b></span></font><br>
</div>
<div style=""><font color="#1f497d" face="Verdana, sans-serif" data-ogsc="" style=""><span style="font-size:12px"><i>Network Administrator</i></span></font><br>
<div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0px 0in 0.000133333px; text-align: start; background-color: rgb(255, 255, 255);">
<a href="https://ims.consulting/" title="https://ims.consulting/"><img class="EmojiInsert" style="max-width:100%" data-outlook-trace="F:1|T:1" src="cid:fb7cfde8-629e-46a8-9eb4-57776243d315"></a><br>
</div>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);">Infrastructure Management Solutions, LLC</span><span style="margin: 0px; color: black;"></span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);"></span></p>
<p style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);">Washington, DC</span></p>
<p style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);">Los Angeles, CA</span></p>
<p style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);">New York, NY</span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);"></span><span style="margin: 0px; color: black;"></span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);">Office: 800.764.6685</span><span style="margin: 0px; color: black;"></span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);">Fax: 703.842.8917</span><span style="margin: 0px; color: black;"></span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: rgb(31, 73, 125);">Mobile: 914.589.5879</span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; color: rgb(47, 84, 150);"><span style="margin:0px">ptedesco@ims.consulting</span><br>
</span><span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: black;"><a href="http://ims.consulting/" target="_blank" rel="noopener noreferrer" style="margin:0px"><span style="margin: 0px; color: blue;">http://ims.consulting</span></a></span><u><span style="margin: 0px; color: blue;"></span></u></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; font-size: 9pt; font-family: Verdana, sans-serif; color: black;"> </span><span style="margin: 0px; color: black;"></span></p>
<div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0px 0in 0.000133333px; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; color: black;"><a href="https://www.linkedin.com/company/infrastructure-management-solutions-llc" title="https://www.linkedin.com/company/infrastructure-management-solutions-llc"><img class="EmojiInsert" style="max-width:100%" data-outlook-trace="F:1|T:1" src="cid:2a2cd2ed-269d-4574-8cea-ab29db36a094"></a></span></div>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; color: black;"> </span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<b><i><span style="margin: 0px; color: rgb(31, 73, 125);">A Certified Virginia Small Business!</span></i></b><span style="margin: 0px; color: black;"></span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<span style="margin: 0px; color: black;"> </span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 11pt; margin: 0in 0in 0.0001pt; text-align: start; background-color: rgb(255, 255, 255);">
<i><span style="margin: 0px; font-size: 10pt; color: rgb(31, 73, 125);">This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail.
Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. E-mail transmission cannot be guaranteed to be secure or error-free as information could be intercepted, corrupted, lost, destroyed,
arrive late or incomplete, or contain viruses. The sender therefore does not accept liability for any errors or missions in the contents of this message, which arise as a result of e-mail transmission.</span></i></p>
</div>
</div>
</div>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size: 11pt;" data-ogsc=""><b>From:</b> users <users-bounces@shibboleth.net> on behalf of users-request@shibboleth.net <users-request@shibboleth.net><br>
<b>Sent:</b> Thursday, August 13, 2020 8:00 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> users Digest, Vol 110, Issue 9</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">Send users mailing list submissions to<br>
users@shibboleth.net<br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
<a href="https://shibboleth.net/mailman/listinfo/users">https://shibboleth.net/mailman/listinfo/users</a><br>
or, via email, send a message with subject or body 'help' to<br>
users-request@shibboleth.net<br>
<br>
You can reach the person managing the list at<br>
users-owner@shibboleth.net<br>
<br>
When replying, please edit your Subject line so it is more specific<br>
than "Re: Contents of users digest..."<br>
<br>
<br>
Today's Topics:<br>
<br>
1. Re: IDP proxy - attribute (Jerry Bailie)<br>
2. Non standard parameter name for SAMLResponse<br>
(Yngvi ??r Sigurj?nsson)<br>
3. Re: Non standard parameter name for SAMLResponse (Cantor, Scott)<br>
4. Re: Open access control for testing (Mathew, Sunil)<br>
5. Re: IDP proxy - attribute (Cantor, Scott)<br>
<br>
<br>
----------------------------------------------------------------------<br>
<br>
Message: 1<br>
Date: Wed, 12 Aug 2020 08:04:39 -0400<br>
From: Jerry Bailie <jebailie@vassar.edu><br>
To: Shib Users <users@shibboleth.net><br>
Subject: Re: IDP proxy - attribute<br>
Message-ID:<br>
<CALAoxZA+fVvsPFYv4mtquPpVjqeV0h-ndn45FpY6trMWQz66Sw@mail.gmail.com><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
#'s 3 and 4, I think we're good to go.<br>
<br>
1 and 2, not so much...<br>
<br>
I see this in the idp-process.log:<br>
<br>
2020-08-12 07:53:45,847 - x.x.x.x - INFO<br>
[net.shibboleth.idp.saml.saml2.profile.impl.ValidateSAMLAuthentication:443]<br>
- Profile Action ValidateSAMLAuthentication: No transcoding rule for<br>
Attribute 'eduPersonScopedAffiliation'<br>
<br>
<br>
So we know that it is being 'exported' out of the proxy. This is true<br>
because I can turn it 'off' on the proxy end and this message does not<br>
present itself in the log.<br>
<br>
This is what we have in attribute-filter.xml :<br>
<br>
<AttributeFilterPolicy id="proxy"><br>
<PolicyRequirementRule xsi:type="Issuer" value="<br>
<a href="https://vassar.onelogin.com">https://vassar.onelogin.com</a>" /><br>
<AttributeRule attributeID="eduPersonScopedAffiliation"><br>
<PermitValueRule xsi:type="ANY" /><br>
</AttributeRule><br>
</AttributeFilterPolicy><br>
<br>
1) What should the "value" of the issuer be? When the xsi:type is<br>
"Requester", it is <a href="http://www.example.com/sp">www.example.com/sp</a> or some such related to the SP.<br>
2) It's not clear how to 'map' the incoming attribute to a Transcoding rule.<br>
<br>
- Jerry<br>
<br>
On Tue, Aug 11, 2020 at 3:34 PM Cantor, Scott <cantor.2@osu.edu> wrote:<br>
<br>
> On 8/11/20, 3:12 PM, "users on behalf of Jerry Bailie" <<br>
> users-bounces@shibboleth.net on behalf of jebailie@vassar.edu> wrote:<br>
><br>
> > The question is, is how to obtain that attribute<br>
> (eduPersonScopedAffiliation) from Onelogin ?<br>
><br>
> <a href="https://wiki.shibboleth.net/confluence/display/IDP4/SAMLAuthnConfiguration">
https://wiki.shibboleth.net/confluence/display/IDP4/SAMLAuthnConfiguration</a><br>
><br>
> Attribute Extraction and Filtering<br>
> Attribute Resolution<br>
><br>
> i.e.<br>
><br>
> 1. Make sure the Attribute Registry transcoding rules map the necessary<br>
> SAML Attribute(s) into their internal IDs.<br>
> 2. Add filter rules as required to accept those attribute IDs from the<br>
> "issuer".<br>
> 3. Add a Subject data connector to export the attribute(s) back out of the<br>
> resolver.<br>
> 4. Add filter rules as required to release the attribute IDs to the SP.<br>
><br>
> That's generally all it takes unless the use case is more complex.<br>
><br>
> (3) automates all the complex parts that are happening under the covers.<br>
><br>
> -- Scott<br>
><br>
><br>
> --<br>
> For Consortium Member technical support, see<br>
> <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
> To unsubscribe from this list send an email to<br>
> users-unsubscribe@shibboleth.net<br>
><br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20200812/e34aa464/attachment-0001.htm">http://shibboleth.net/pipermail/users/attachments/20200812/e34aa464/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 2<br>
Date: Wed, 12 Aug 2020 14:24:23 +0000<br>
From: Yngvi ??r Sigurj?nsson <blitzkopf@gmail.com><br>
To: users@shibboleth.net<br>
Subject: Non standard parameter name for SAMLResponse<br>
Message-ID:<br>
<CAFeGNAoSNK+CfhjvcfaPTmmxS-3HZUTaVURWVST-8euNieY6sA@mail.gmail.com><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
Hi!<br>
I'm trying to integrate Shibboleth Service Provider with an IdP (<br>
innskraning.island.is ) that claims to use SAML 2 but I believe it is a<br>
half baked attempt.<br>
<br>
The Response is posted in application/x-www-form-urlencoded body but the<br>
name of the parameter is token like so<br>
token=PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGlu......<br>
<br>
I still believe the response received is a valid Response but I get this<br>
message from Shibboleth<br>
Request missing SAMLRequest or SAMLResponse form parameter.<br>
<br>
Is there a way to configure the parameter name (SAMLResponse) expected to<br>
hold the response?<br>
<br>
Regards<br>
Yngvi<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20200812/ae6906da/attachment-0001.htm">http://shibboleth.net/pipermail/users/attachments/20200812/ae6906da/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 3<br>
Date: Wed, 12 Aug 2020 14:28:09 +0000<br>
From: "Cantor, Scott" <cantor.2@osu.edu><br>
To: Shib Users <users@shibboleth.net><br>
Subject: Re: Non standard parameter name for SAMLResponse<br>
Message-ID: <09669722-CA28-4113-B6D8-70307DC38053@osu.edu><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
On 8/12/20, 10:24 AM, "users on behalf of Yngvi ??r Sigurj?nsson" <users-bounces@shibboleth.net on behalf of blitzkopf@gmail.com> wrote:<br>
<br>
> Is there a way to configure the parameter name (SAMLResponse) expected to hold the response?<br>
<br>
No.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 4<br>
Date: Wed, 12 Aug 2020 19:09:15 +0000<br>
From: "Mathew, Sunil" <smathew@hbs.edu><br>
To: Shib Users <users@shibboleth.net><br>
Subject: Re: Open access control for testing<br>
Message-ID: <8DF73AFE-C93B-4C85-B923-DE7412C0C980@hbs.edu><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
We just added the VPN NAT address t o access control and that worked.<br>
<br>
<entry key="AccessByIPAddress"><br>
<bean id="AccessByIPAddress" parent="shibboleth.IPRangeAccessControl"<br>
p:allowedRanges="#{ {'199.94.00.00/32', '127.0.0.1/32', '::1/128'} }" /><br>
</entry><br>
<br>
PS: This is a test environment that we are setting up Shibboleth in ECS and the security group is limiting to clients only from VPN ip address.<br>
<br>
Sunil<br>
<br>
<br>
?On 8/12/20, 4:02 AM, "users on behalf of Peter Schober" <users-bounces@shibboleth.net on behalf of peter.schober@univie.ac.at> wrote:<br>
<br>
* Mathew, Sunil <smathew@hbs.edu> [2020-08-11 19:20]:<br>
> Here is my problem. I deployed Shibboleth to ECS. But I was getting the following error in IdP logs:<br>
> <br>
> IDP_WARN: 2020-08-10 17:33:37,057 - 10.140.0.162 - ERROR<br>
> [org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:200]<br>
> - Message Handler: SAML message intended destination endpoint<br>
> '<a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsso.hbsstg.org%2Fidp%2Fprofile%2FSAML2%2FRedirect%2FSSO&data=02%7C01%7Csmathew%40hbs.edu%7Cde308d73e83d4630d4d408d83e96064e%7C09fd564ebf4243218f2db8e482f8635c%7C0%7C0%7C637328161378736967&sdata=iOWEEcNGiTmOYRS2Pq1mNdoaO1wGpjkR5bMREojkobs%3D&reserved=0">https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsso.hbsstg.org%2Fidp%2Fprofile%2FSAML2%2FRedirect%2FSSO&data=02%7C01%7Csmathew%40hbs.edu%7Cde308d73e83d4630d4d408d83e96064e%7C09fd564ebf4243218f2db8e482f8635c%7C0%7C0%7C637328161378736967&sdata=iOWEEcNGiTmOYRS2Pq1mNdoaO1wGpjkR5bMREojkobs%3D&reserved=0</a>'
did not<br>
> match the recipient endpoint<br>
> '<a href="https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsso.hbsstg.org%2Fidp%2Fprofile%2FSAML2%2FRedirect%2FSSO&data=02%7C01%7Csmathew%40hbs.edu%7Cde308d73e83d4630d4d408d83e96064e%7C09fd564ebf4243218f2db8e482f8635c%7C0%7C0%7C637328161378741957&sdata=pX6yxbFNPshWQdKyZI2v%2Bmt2e8Rm53F7pSqP2l%2FhmZs%3D&reserved=0">https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsso.hbsstg.org%2Fidp%2Fprofile%2FSAML2%2FRedirect%2FSSO&data=02%7C01%7Csmathew%40hbs.edu%7Cde308d73e83d4630d4d408d83e96064e%7C09fd564ebf4243218f2db8e482f8635c%7C0%7C0%7C637328161378741957&sdata=pX6yxbFNPshWQdKyZI2v%2Bmt2e8Rm53F7pSqP2l%2FhmZs%3D&reserved=0</a>'<br>
[...]<br>
> requestScheme:http<br>
> requestIsSecure:false<br>
> requestServerPort:80<br>
> <br>
> We are trying to add tomcat valve with<br>
> protocolHeader="x-forwarded-proto" so that we can get past the<br>
> error.<br>
<br>
Alternatively you could try setting the relevant attributes on the<br>
relevant Tomcat (plain) HTTP Connector, e.g.<br>
<br>
proxyPort="443"<br>
scheme="https"<br>
secure="true"<br>
<br>
Of course you need to make sure there's no plain HTTP traffic being<br>
accepted/forward to/from your TLS offloading service. (And IDP doesn't<br>
need plain HTTP support, not even with redirects to HTTPS, so just<br>
bock all non-HTTPS requests at the TLS offloading service.)<br>
<br>
Cheers,<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7Csmathew%40hbs.edu%7Cde308d73e83d4630d4d408d83e96064e%7C09fd564ebf4243218f2db8e482f8635c%7C0%7C0%7C637328161378741957&sdata=C7yQbZDYtVik6b3R%2BfiFsxQNtdnAyjqymTcL22bPuCU%3D&reserved=0">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7Csmathew%40hbs.edu%7Cde308d73e83d4630d4d408d83e96064e%7C09fd564ebf4243218f2db8e482f8635c%7C0%7C0%7C637328161378741957&sdata=C7yQbZDYtVik6b3R%2BfiFsxQNtdnAyjqymTcL22bPuCU%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
<br>
<br>
------------------------------<br>
<br>
Message: 5<br>
Date: Wed, 12 Aug 2020 23:08:28 +0000<br>
From: "Cantor, Scott" <cantor.2@osu.edu><br>
To: Shib Users <users@shibboleth.net><br>
Subject: Re: IDP proxy - attribute<br>
Message-ID: <BD56F869-2E66-439F-8F91-54B419872DDA@osu.edu><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
> So we know that it is being 'exported' out of the proxy. <br>
<br>
No, some bogus, made-up SAML Attribute that is *not* defined by eduPerson is being exported. eduPerson attributes in SAML 2 have names derived from OIDs in the form of URNs. The defined mapping rules are correct out of the box. Passing data that is not correct
will not be processed, and the message reflects that.<br>
<br>
> 1) What should the "value" of the issuer be? <br>
<br>
The entityID of the IdP you're proxying to is the issuer for a rule that handles acceptance, it's just the inverse of a release rule.<br>
<br>
> 2) It's not clear how to 'map' the incoming attribute to a Transcoding rule.<br>
<br>
I wouldn't in this particular case, but the documentation on creating custom rules is in the wiki.<br>
<br>
<a href="https://wiki.shibboleth.net/confluence/display/IDP4/AttributeRegistryConfiguration">https://wiki.shibboleth.net/confluence/display/IDP4/AttributeRegistryConfiguration</a><br>
<br>
-- Scott<br>
<br>
<br>
<br>
------------------------------<br>
<br>
Subject: Digest Footer<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
<br>
<br>
------------------------------<br>
<br>
End of users Digest, Vol 110, Issue 9<br>
*************************************<br>
</div>
</span></font></div>
</div>
</body>
</html>