<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
</head>
<body>
The isMemberOF attribute is an operational attribute on the user.
The uniquemember (or member) attribute is an attribute on the group
(showing all user's that are in the group).<br>
<br>
You should be able to use the LDAP service/utility account that
you've configured Shibboleth to use and perform an ldapsearch
against your LDAP service and ask the ldapsearch to return
"returnAttributes" you are listing below.<br>
<br>
<br>
Using OpenLDAP's ldapsearch in this example:<br>
<br>
<font face="monospace">ldapsearch -x -LLL -h yourLDAPserver -p 389
-D myShibbolethServiceAccount -W -Z -b ou=People,dc=example,dc=org
"(uid=awong)" displayName mail uid sn givenName isMemberOf<br>
</font><br>
The search should return the 6 requested attributes. You might have
to add an ACL for the isMemberOf attribute to your LDAP server so
your Shibboleth service/utility account can see it.<br>
<br>
Don<br>
<br>
<div class="moz-cite-prefix">On 11/30/20 10:01 AM, Feinstein, Moses
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:BL0PR0102MB34578C2571BEF5E23D876475FBF50@BL0PR0102MB3457.prod.exchangelabs.com">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--> <span style="font-size: 10pt; color:
black; background: rgb(255, 235, 156);"></span>
<hr>
<div>
<div class="WordSection1">
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am trying to return group membership
for the user who is authenticating via Shibboleth 4.0.1<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Below configuration works, if I
substitute “isMemberOf” in attribute resolver with any other
attribute (displayName for example), however for some reason
it is unable to read “isMemberOf”, it returns nothing for
the group membership even though the user is a member of the
group (cn=testgroup,ou=Groups,dc=example,dc=org).
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Since “isMemberOf” is part of operational
attributes, I am not sure if there is anything else that
needs to be configured on Shibboleth side.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Am I missing something in my
configuration below to be able to read operational attribute
“isMemberOf” from the LDAP?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">If anyone has a good example on how to
read group membership it would be very helpful. Thanks.
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Attribute-filter:<o:p></o:p></p>
<p class="MsoNormal">
<AttributeRule attributeID="membership" permitAny="true"
/><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Ldap.properties:<o:p></o:p></p>
<p class="MsoNormal">
idp.attribute.resolver.LDAP.returnAttributes =
displayName,mail,uid,sn,givenName,isMemberOf<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Attribute-resolver:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in;text-indent:.5in"><AttributeDefinition
xsi:type="Simple" id="isMemberOf"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<InputDataConnector ref="myLDAP"
attributeNames="isMemberOf" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"></AttributeDefinition><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><AttributeDefinition
id="membership" xsi:type="Mapped"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<InputAttributeDefinition ref="isMemberOf" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<DefaultValue passThru="true"/><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<ValueMap><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<ReturnValue>return_membership</ReturnValue><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<SourceValue
caseSensitive="false">cn=testgroup,ou=Groups,dc=example,dc=org</SourceValue><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
</ValueMap><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<AttributeEncoder xsi:type="SAML2String"
name="membership" friendlyName="membership"
encodeType="false" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"></AttributeDefinition><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Ldap user is part of this group:<o:p></o:p></p>
<p class="MsoNormal">
uid=awong,ou=People,dc=example,dc=org<o:p></o:p></p>
<p class="MsoNormal" style="text-indent:.5in">isMemberOf:
cn=testgroup,ou=Groups,dc=example,dc=org<o:p></o:p></p>
<p class="MsoNormal"><b><span
style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span
style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span
style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-size:8.0pt">Moses
Feinstein<o:p></o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:8.0pt">Touro
College and University System<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>