<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
</head>
<body>
<font face="monospace">OOPS:<br>
<br>
ldapsearch -x -LLL -h yourLDAPserver -p 389 -D
uid=myShibbolethServiceAccount -W -Z -b
ou=People,dc=example,dc=org "(uid=awong)" displayName mail uid sn
givenName isMemberOf</font><br>
<br>
<div class="moz-cite-prefix">On 11/30/20 12:24 PM, Donald Lohr
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:6d838576-9afd-ee3d-4529-8cf99f08e8c9@jmu.edu">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<span style="font-size: 10pt; color: black; background: rgb(255,
235, 156);"></span>
<hr>
<div>The isMemberOF attribute is an operational attribute on the
user. The uniquemember (or member) attribute is an attribute on
the group (showing all user's that are in the group).<br>
<br>
You should be able to use the LDAP service/utility account that
you've configured Shibboleth to use and perform an ldapsearch
against your LDAP service and ask the ldapsearch to return
"returnAttributes" you are listing below.<br>
<br>
<br>
Using OpenLDAP's ldapsearch in this example:<br>
<br>
<font face="monospace">ldapsearch -x -LLL -h yourLDAPserver -p
389 -D myShibbolethServiceAccount -W -Z -b
ou=People,dc=example,dc=org "(uid=awong)" displayName mail uid
sn givenName isMemberOf<br>
</font><br>
The search should return the 6 requested attributes. You might
have to add an ACL for the isMemberOf attribute to your LDAP
server so your Shibboleth service/utility account can see it.<br>
<br>
Don<br>
<br>
<div class="moz-cite-prefix">On 11/30/20 10:01 AM, Feinstein,
Moses wrote:<br>
</div>
<blockquote type="cite"
cite="mid:BL0PR0102MB34578C2571BEF5E23D876475FBF50@BL0PR0102MB3457.prod.exchangelabs.com">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--> <span style="font-size: 10pt; color:
black; background: rgb(255, 235, 156);"></span>
<hr>
<div>
<div class="WordSection1">
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am trying to return group
membership for the user who is authenticating via
Shibboleth 4.0.1<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Below configuration works, if I
substitute “isMemberOf” in attribute resolver with any
other attribute (displayName for example), however for
some reason it is unable to read “isMemberOf”, it
returns nothing for the group membership even though the
user is a member of the group
(cn=testgroup,ou=Groups,dc=example,dc=org). <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Since “isMemberOf” is part of
operational attributes, I am not sure if there is
anything else that needs to be configured on Shibboleth
side.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Am I missing something in my
configuration below to be able to read operational
attribute “isMemberOf” from the LDAP?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">If anyone has a good example on how
to read group membership it would be very helpful.
Thanks. <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Attribute-filter:<o:p></o:p></p>
<p class="MsoNormal">
<AttributeRule attributeID="membership"
permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Ldap.properties:<o:p></o:p></p>
<p class="MsoNormal">
idp.attribute.resolver.LDAP.returnAttributes =
displayName,mail,uid,sn,givenName,isMemberOf<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Attribute-resolver:<o:p></o:p></p>
<p class="MsoNormal"
style="margin-left:.5in;text-indent:.5in"><AttributeDefinition
xsi:type="Simple" id="isMemberOf"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<InputDataConnector ref="myLDAP"
attributeNames="isMemberOf" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"></AttributeDefinition><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><AttributeDefinition
id="membership" xsi:type="Mapped"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<InputAttributeDefinition ref="isMemberOf" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<DefaultValue passThru="true"/><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<ValueMap><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<ReturnValue>return_membership</ReturnValue><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<SourceValue
caseSensitive="false">cn=testgroup,ou=Groups,dc=example,dc=org</SourceValue><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
</ValueMap><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:1.0in">
<AttributeEncoder xsi:type="SAML2String"
name="membership" friendlyName="membership"
encodeType="false" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"></AttributeDefinition><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Ldap user is part of this group:<o:p></o:p></p>
<p class="MsoNormal">
uid=awong,ou=People,dc=example,dc=org<o:p></o:p></p>
<p class="MsoNormal" style="text-indent:.5in">isMemberOf:
cn=testgroup,ou=Groups,dc=example,dc=org<o:p></o:p></p>
<p class="MsoNormal"><b><span
style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span
style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span
style="font-size:8.0pt;font-family:Consolas;color:#44546A"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-size:8.0pt">Moses
Feinstein<o:p></o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:8.0pt">Touro
College and University System<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>