<html><head></head><body><div class="ydp96478e12yahoo-style-wrap" style="font-family:Helvetica Neue, Helvetica, Arial, sans-serif;font-size:13px;"><div></div>
        <div dir="ltr" data-setdir="false"><div><div style="color: rgb(0, 0, 0); font-family: Helvetica Neue, Helvetica, Arial, sans-serif;">We were using old Shibboleth build, the existing oid mapping is not work after upgrade to V3. </div><div dir="ltr" data-setdir="false" style="color: rgb(0, 0, 0); font-family: Helvetica Neue, Helvetica, Arial, sans-serif;">Upgrade to V4 is not an option for us for now.</div><div style="color: rgb(0, 0, 0); font-family: Helvetica Neue, Helvetica, Arial, sans-serif;">Yes, this is trying ADFS SAML 2 SP with Shibboleth V3 IdP. </div></div><br></div><div dir="ltr" data-setdir="false">thanks,</div><div dir="ltr" data-setdir="false">SC</div><div><br></div>
        
        </div><div id="ydp7d201ac1yahoo_quoted_5836859476" class="ydp7d201ac1yahoo_quoted">
            <div style="font-family:'Helvetica Neue', Helvetica, Arial, sans-serif;font-size:13px;color:#26282a;">
                
                <div>
                    On Friday, November 13, 2020, 09:28:57 AM PST, Peter Schober <peter.schober@univie.ac.at> wrote:
                </div>
                <div><br></div>
                <div><br></div>
                <div>Is there a relation between the Subject line of your post and the<br clear="none">content of your post? Something about upgrading a Shibboleth IDP?<br clear="none">Possibly to version 4?<br clear="none"><br clear="none">More comments/questions below.<br clear="none"><br clear="none">* s chang via users <<a shape="rect" href="mailto:users@shibboleth.net" rel="nofollow" target="_blank">users@shibboleth.net</a>> [2020-11-13 18:13]:<br clear="none">> We are trying to deploy Shibboleth V3 (3.4.7.1) with ADFS 3.0.<br clear="none"><br clear="none">Do you mean you're trying to use ADFS as a SAML 2.0 SP with your<br clear="none">Shibboleth v3 IDP?<br clear="none"><br clear="none">> Set up "Edit claim rules for Claim provider trust" failed.<br clear="none"><br clear="none">Should that mean anything to us? That's not something from the<br clear="none">Shibboleth documentation, is it?<br clear="none"><br clear="none">> On Custom Rule, we tried below rule. But OID and name  seems outdated<br clear="none"><br clear="none">Outdated how?<br clear="none">How did you come to the conclusion that an OID or name was "outdated"?<br clear="none"><br clear="none">> Does anyone know what is the latest Shibboleth’s OID to map to<br clear="none">> ADFS’s claim type “Name” and “UPN” below?<br clear="none">> c:[Type == "urn:oid:1.3.6.1.4.1.5923.1.1.1.6", Value=~<br clear="none">> "^.+@adatum.com$"]=> issue(Type =<br clear="none">> "<a shape="rect" href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" rel="nofollow" target="_blank">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name</a>",Issuer<br clear="none">> = c.Issuer, OriginalIssuer = c.OriginalIssuer, Value =<br clear="none">> c.Value,ValueType = c.ValueType);<br clear="none"><br clear="none">I don't understand the question. Shibboleth has no OIDs of its own,<br clear="none">the software can be configured to use whatever formal attribute names<br clear="none">you want to use/support.<br clear="none"><br clear="none">I don't speak "ADSF claims" myself so I cannot tell what the above<br clear="none">does or means or how that's related to the eduPersonPrincipalName<br clear="none">attribute (defined in the eduPerson-specification) whose OID you have<br clear="none">included above.<br clear="none"><br clear="none">Best regards,<br clear="none">-peter<div class="ydp7d201ac1yqt5439886255" id="ydp7d201ac1yqtfd04532"><br clear="none">-- <br clear="none">For Consortium Member technical support, see <a shape="rect" href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="nofollow" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br clear="none">To unsubscribe from this list send an email to <a shape="rect" href="mailto:users-unsubscribe@shibboleth.net" rel="nofollow" target="_blank">users-unsubscribe@shibboleth.net</a><br clear="none"></div></div>
            </div>
        </div></body></html>