<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body>
    <font face="monospace">OOPS:<br>
      <br>
      ldapsearch -x -LLL -h yourLDAPserver -p 389 -D
      uid=myShibbolethServiceAccount -W -Z -b
      ou=People,dc=example,dc=org "(uid=awong)" displayName mail uid sn
      givenName isMemberOf</font><br>
    <br>
    <div class="moz-cite-prefix">On 11/30/20 12:24 PM, Donald Lohr
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:6d838576-9afd-ee3d-4529-8cf99f08e8c9@jmu.edu">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <span style="font-size: 10pt; color: black; background: rgb(255,
        235, 156);"></span>
      <hr>
      <div>The isMemberOF attribute is an operational attribute on the
        user. The uniquemember (or member) attribute is an attribute on
        the group (showing all user's that are in the group).<br>
        <br>
        You should be able to use the LDAP service/utility account that
        you've configured Shibboleth to use and perform an ldapsearch
        against your LDAP service and ask the ldapsearch to return
        "returnAttributes" you are listing below.<br>
        <br>
        <br>
        Using OpenLDAP's ldapsearch in this example:<br>
        <br>
        <font face="monospace">ldapsearch -x -LLL -h yourLDAPserver -p
          389 -D myShibbolethServiceAccount -W -Z -b
          ou=People,dc=example,dc=org "(uid=awong)" displayName mail uid
          sn givenName isMemberOf<br>
        </font><br>
        The search should return the 6 requested attributes. You might
        have to add an ACL for the isMemberOf attribute to your LDAP
        server so your Shibboleth service/utility account can see it.<br>
        <br>
        Don<br>
        <br>
        <div class="moz-cite-prefix">On 11/30/20 10:01 AM, Feinstein,
          Moses wrote:<br>
        </div>
        <blockquote type="cite"
cite="mid:BL0PR0102MB34578C2571BEF5E23D876475FBF50@BL0PR0102MB3457.prod.exchangelabs.com">
          <meta name="Generator" content="Microsoft Word 15 (filtered
            medium)">
          <style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--> <span style="font-size: 10pt; color:
            black; background: rgb(255, 235, 156);"></span>
          <hr>
          <div>
            <div class="WordSection1">
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">I am trying to return group
                membership for the user who is authenticating via
                Shibboleth 4.0.1<o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">Below configuration works, if I
                substitute “isMemberOf” in attribute resolver with any
                other attribute (displayName for example), however for
                some reason it is unable to read “isMemberOf”, it
                returns nothing for the group membership even though the
                user is a member of the group
                (cn=testgroup,ou=Groups,dc=example,dc=org). <o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">Since “isMemberOf” is part of
                operational attributes, I am not sure if there is
                anything else that needs to be configured on Shibboleth
                side.<o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">Am I missing something in my
                configuration below to be able to read operational
                attribute “isMemberOf” from the LDAP?<o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">If anyone has a good example on how
                to read group membership it would be very helpful.
                Thanks. <o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">Attribute-filter:<o:p></o:p></p>
              <p class="MsoNormal">                             
                 <AttributeRule attributeID="membership"
                permitAny="true" /><o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">Ldap.properties:<o:p></o:p></p>
              <p class="MsoNormal">                             
                idp.attribute.resolver.LDAP.returnAttributes         =
                displayName,mail,uid,sn,givenName,isMemberOf<o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">Attribute-resolver:<o:p></o:p></p>
              <p class="MsoNormal"
                style="margin-left:.5in;text-indent:.5in"><AttributeDefinition
                xsi:type="Simple" id="isMemberOf"><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">   
                <InputDataConnector ref="myLDAP"
                attributeNames="isMemberOf" /><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in"></AttributeDefinition><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in"><o:p> </o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in"><AttributeDefinition
                id="membership" xsi:type="Mapped"><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">   
                <InputAttributeDefinition ref="isMemberOf" /><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in"> 
                  <DefaultValue passThru="true"/><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">              
                <o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">              
                <ValueMap><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">                             
                <ReturnValue>return_membership</ReturnValue><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">                             
                <SourceValue
caseSensitive="false">cn=testgroup,ou=Groups,dc=example,dc=org</SourceValue><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">              
                </ValueMap><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in"><o:p> </o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in">   
                <AttributeEncoder xsi:type="SAML2String"
                name="membership" friendlyName="membership"
                encodeType="false" /><o:p></o:p></p>
              <p class="MsoNormal" style="margin-left:1.0in"></AttributeDefinition><o:p></o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal">Ldap user is part of this group:<o:p></o:p></p>
              <p class="MsoNormal">              
                uid=awong,ou=People,dc=example,dc=org<o:p></o:p></p>
              <p class="MsoNormal" style="text-indent:.5in">isMemberOf:
                cn=testgroup,ou=Groups,dc=example,dc=org<o:p></o:p></p>
              <p class="MsoNormal"><b><span
                    style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
              <p class="MsoNormal"><b><span
                    style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
              <p class="MsoNormal"><b><span
                    style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
              <p class="MsoNormal"><b><span style="font-size:8.0pt">Moses
                    Feinstein<o:p></o:p></span></b></p>
              <p class="MsoNormal"><span style="font-size:8.0pt">Touro
                  College and University System<o:p></o:p></span></p>
              <p class="MsoNormal"><o:p> </o:p></p>
              <p class="MsoNormal"><o:p> </o:p></p>
            </div>
          </div>
          <br>
          <fieldset class="mimeAttachmentHeader"></fieldset>
        </blockquote>
        <br>
        <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>