<div dir="ltr"><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">It sounds like your ldap server is configured for case-sensitive searches on memberUid, which I think is pretty standard. That's why your ldap filter is returning no results when the supplied UID doesn't match. You'll either need to change your ldap server (probably not a good idea?), do something to fold the case to lowercase in your FilterTemplate, or live with user education.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">-Les</div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><br><table style="color:rgb(136,136,136);border:none;border-collapse:collapse"><tbody><tr style="height:0pt;border-top:1pt solid rgb(204,204,204)"><td style="border-right:1pt solid rgb(204,204,204);vertical-align:middle;padding:5pt;overflow:hidden"><p dir="ltr" style="line-height:1.2;margin-top:0pt;margin-bottom:0pt"><a href="http://www.carleton.edu/" target="_blank"><span style="font-size:11pt;font-family:Arial;color:rgb(17,85,204);vertical-align:baseline;white-space:pre-wrap"><span style="border:none;display:inline-block;overflow:hidden;width:70px;height:73px"><img height="73" src="https://lh6.googleusercontent.com/QEL1To3Ci_dJA1huaKzfZ0Lf4MaZlAy_f-W3vQjbyzNq_yXq_ZYGv3tuT4dkaZS_bZ5X6fZR4iKzBboZhxbCF5htZFnLNKGqmrzHsVJtsjsy0pfK5w2z0Dlq-EtZcWhv0PxBpWmR" width="70" style="margin-left:0px;margin-top:0px"></span></span></a></p></td><td style="border-left:1pt solid rgb(204,204,204);vertical-align:top;padding:10.8pt;overflow:hidden"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><font color="#dea410" face="Arial"><span style="font-size:14.6667px;white-space:pre-wrap"><b>Les LaCroix '79</b></span></font></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Strategic Technologist</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">Information Technology Services</span></span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="color:rgb(11,80,145)"><span style="font-size:11pt;font-family:Arial;vertical-align:baseline;white-space:pre-wrap">t: (507) 222-5455</span></span></p></td></tr></tbody></table></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Jan 5, 2021 at 9:20 AM Adam Bishop via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">If a user logs into our IDP instance with a mixed case username (e.g. Adam.Bishop rather than adam.bishop), their group membership information is not added to the assertion.<br>
<br>
Using case that matches their UID as stored in ldap (i.e. all lower case), it works as expected. I've reproduced it with my own account - the consent screen has no 'member' attribute in the list if I uppercase my username, and the the SP receives no 'member' attribute.<br>
<br>
We're running 3.4.8, and upgraded a few days after release so it's possible this is recent breakage. Our configuration is fairly default, just password based login flows to <20 non-federated SP's.<br>
<br>
The attribute is defined as:<br>
<br>
<AttributeDefinition id="member" xsi:type="Simple"><br>
<InputDataConnector ref="ipaGroupQuery" attributeNames="cn" /><br>
<AttributeEncoder xsi:type="SAML2String" name="urn:oid:1.3.6.1.4.1.5923.1.5.1.1" friendlyName="member" encodeType="false" /><br>
</AttributeDefinition><br>
<br>
The ldap search filter is:<br>
<FilterTemplate><br>
<![CDATA[<br>
(memberUid=${resolutionContext.principal})<br>
]]><br>
</FilterTemplate><br>
<br>
The release policy is:<br>
<br>
<AttributeFilterPolicy id="releaseToAll"><br>
<PolicyRequirementRule xsi:type="ANY" /><br>
...<br>
<AttributeRule attributeID="member"><br>
<PermitValueRule xsi:type="ANY" /><br>
</AttributeRule><br>
...<br>
</AttributeFilterPolicy><br>
<br>
I've configured additional logging, and I can see that the group query is executed, and does return the list of groups (see end of email) - so what could be going on between the LDAP query and the assertion being sent.<br>
<br>
It'll probably all work if I set shibboleth.authn.Password.Lowercase but that seems like a hack - if the group list is being returned by LDAP, matches the definition, and passes the filter policy it should be included as far as I understand.<br>
<br>
Thanks for any assistance,<br>
<br>
Adam Bishop<br>
Senior security architect (systems)<br>
<br>
gpg: E75B 1F92 6407 DFDF 9F1C BF10 C993 2504 6609 D460<br>
<br>
<a href="http://jisc.ac.uk" rel="noreferrer" target="_blank">jisc.ac.uk</a><br>
<br>
---<br>
<br>
2021-01-05 14:47:29,873 - 88.98.83.40 - DEBUG [org.ldaptive.SearchOperation:168] - execute response=[org.ldaptive.Response@1501309882::result=[org.ldaptive.SearchResult@-887324086::entries=[[dn=uid=user,cn=users,cn=accounts,dc=domain[[mail[<a href="mailto:user.name@jisc.ac.uk" target="_blank">user.name@jisc.ac.uk</a>]], [ipaUniqueID[**snip**]], [krbLastPwdChange[20200421092040Z]], [title[Normal User]], [objectClass[inetuser, ipasshuser, ipantuserattrs, inetorgperson, ipaobject, krbprincipalaux, organizationalperson, top, person, ipauserauthtypeclass, krbticketpolicyaux, ipaSshGroupOfPubKeys, mepOriginEntry, posixaccount]], [loginShell[/bin/bash]], [uid[user]], [krbPasswordExpiration[20210421092040Z]], [homeDirectory[/home/user]], [givenName[User]], [ipaSshPubKey[*snip*]], [sn[Name]], [entryDN[uid=user,cn=users,cn=accounts,dc=domain]], [manager[uid=user,cn=users,cn=accounts,dc=domain]], [ipaNTSecurityIdentifier[**snip**]], [ou[Null]], [initials[UN]], [gidNumber[100]], [krbPrincipalName[user@DOMAIN]], [cn[User Name]], [uidNumber[100]], [gecos[User Name]], [displayName[User Name]], [memberOf[<br>
<br>
** snip giant list of groups **<br>
<br>
]], [ipaUserAuthType[otp]]], responseControls=null, messageId=-1]], references=[]], resultCode=SUCCESS, message=null, matchedDn=null, responseControls=null, referralURLs=null, messageId=-1] for request=[org.ldaptive.SearchRequest@-32050967::baseDn=cn=users,cn=accounts,dc=domain, searchFilter=[org.ldaptive.SearchFilter@664361842::filter=(uid=USER), parameters={}], returnAttributes=[], searchScope=SUBTREE, timeLimit=3000, sizeLimit=1, derefAliases=null, typesOnly=false, binaryAttributes=null, sortBehavior=UNORDERED, searchEntryHandlers=[[org.ldaptive.handler.DnAttributeEntryHandler@-1580910376::dnAttributeName=entryDN, addIfExists=false]], searchReferenceHandlers=null, controls=null, followReferrals=false, intermediateResponseHandlers=null] with connection=[org.ldaptive.DefaultConnectionFactory$DefaultConnection@1379181151::config=[org.ldaptive.ConnectionConfig@139698044::ldapUrl=ldaps://server1.domain:636 ldaps://server2.domain:636, connectTimeout=3000, responseTimeout=3000, sslConfig=[org.ldaptive.ssl.SslConfig@1806414996::credentialConfig=org.ldaptive.ssl.CredentialConfigFactory$2@7563ad67, trustManagers=null, hostnameVerifier=null, hostnameVerifierConfig=null, enabledCipherSuites=null, enabledProtocols=null, handshakeCompletedListeners=null], useSSL=false, useStartTLS=false, connectionInitializer=[org.ldaptive.BindConnectionInitializer@1511278406::bindDn=uid=sso-bind,cn=users,cn=accounts,dc=domain, bindSaslConfig=null, bindControls=null]], providerConnectionFactory=[org.ldaptive.provider.jndi.JndiConnectionFactory@1840180882::metadata=[ldapUrl=ldaps://server1.domain:636 ldaps://server2.domain:636, count=1], environment={java.naming.ldap.factory.socket=org.ldaptive.ssl.ThreadLocalTLSSocketFactory, com.sun.jndi.ldap.connect.timeout=3000, java.naming.ldap.version=3, java.naming.factory.initial=com.sun.jndi.ldap.LdapCtxFactory, com.sun.jndi.ldap.read.timeout=3000}, providerConfig=[org.ldaptive.provider.jndi.JndiProviderConfig@1584406844::operationExceptionResultCodes=[PROTOCOL_ERROR, SERVER_DOWN], properties={}, connectionStrategy=org.ldaptive.provider.ConnectionStrategies$ActivePassiveConnectionStrategy@6534274a, controlProcessor=org.ldaptive.provider.ControlProcessor@57e4f242, environment=null, tracePackets=null, removeDnUrls=true, searchIgnoreResultCodes=[TIME_LIMIT_EXCEEDED, SIZE_LIMIT_EXCEEDED, PARTIAL_RESULTS], sslSocketFactory=null, hostnameVerifier=null]], providerConnection=org.ldaptive.provider.jndi.JndiConnection@5ad91aa0]<br>
<br>
<br>
<br>
<br>
<br>
Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under company number. 05747339, VAT number GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
<br>
Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
<br>
Jisc Commercial Limited is a wholly owned Jisc subsidiary and a company limited by shares which is registered in England under company number 09316933, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
<br>
For more details on how Jisc handles your data see our privacy notice here: <a href="https://www.jisc.ac.uk/website/privacy-notice" rel="noreferrer" target="_blank">https://www.jisc.ac.uk/website/privacy-notice</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>