<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Trebuchet MS";
panose-1:2 11 6 3 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style></head><body lang=EN-US link=blue vlink=purple style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal>Hi,<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>The main issue I have found with Azure proxy is that Azure does not send format information to the IDP. Thus you need to specify the format as unspecified when you setup an encoder. Please see my below example where I am creating prxAttrib with the saml2.nameFormat=<span style='font-size:10.0pt;font-family:"Courier New";color:#067D17'> </span>urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified. <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Thanks,<o:p></o:p></p><p class=MsoNormal>--David<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>--Example attrib.properties encoder--<o:p></o:p></p><p class=MsoNormal style='background:white'><span style='font-size:10.0pt;font-family:"Courier New";color:#083080'>id</span><span style='font-size:10.0pt;font-family:"Courier New";color:#080808'>=</span><span style='font-size:10.0pt;font-family:"Courier New";color:#067D17'>prxAttrib<br></span><span style='font-size:10.0pt;font-family:"Courier New";color:#083080'>transcoder</span><span style='font-size:10.0pt;font-family:"Courier New";color:#080808'>=</span><span style='font-size:10.0pt;font-family:"Courier New";color:#067D17'>SAML2ScopedStringTranscoder<br></span><span style='font-size:10.0pt;font-family:"Courier New";color:#083080'>saml2.name</span><span style='font-size:10.0pt;font-family:"Courier New";color:#080808'>=urn:oid:</span><span style='font-size:10.0pt;font-family:"Courier New";color:#067D17'>Attribute<br></span><span style='font-size:10.0pt;font-family:"Courier New";color:#083080'>saml2.nameFormat</span><span style='font-size:10.0pt;font-family:"Courier New";color:#080808'>=</span><span style='font-size:10.0pt;font-family:"Courier New";color:#067D17'>urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified<br></span><span style='font-size:10.0pt;font-family:"Courier New";color:#083080'>saml2.encodeType</span><span style='font-size:10.0pt;font-family:"Courier New";color:#080808'>=</span><span style='font-size:10.0pt;font-family:"Courier New";color:#067D17'>false</span><span style='font-size:10.0pt;font-family:"Courier New";color:#080808'><o:p></o:p></span></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='font-size:12.0pt;color:black'>From: </span></b><span style='font-size:12.0pt;color:black'>users <users-bounces@shibboleth.net> on behalf of "Raja V, Scientist - C (CS)" <raja@inflibnet.ac.in><br><b>Reply-To: </b>Shib Users <users@shibboleth.net><br><b>Date: </b>Monday, February 1, 2021 at 1:00 AM<br><b>To: </b>Shib Users <users@shibboleth.net><br><b>Cc: </b>Francis Jayakanth <Francis@iisc.ac.in><br><b>Subject: </b>[External] Azure AD and shibboleth IdP integration<o:p></o:p></span></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><p class=MsoNormal style='background:#FFECE5'><span style='font-size:9.0pt;font-family:"Arial",sans-serif;color:#82270D'>This message was sent from a non-IU address. Please exercise caution when clicking links or opening attachments from external sources.<o:p></o:p></span></p><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal><span style='font-family:"Trebuchet MS",sans-serif'>Hi,</span><o:p></o:p></p><div><p class=MsoNormal><span style='font-family:"Trebuchet MS",sans-serif'>We are trying to integrate Azure AD with shibboleth by following document available at <a href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD</a></span><o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal><span style='font-family:"Trebuchet MS",sans-serif'>However, after authentication, we are getting the following error. Can anyone help us out?</span><o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal><i><span style='font-family:"Trebuchet MS",sans-serif;color:black;background:yellow'>2021-02-01 11:21:53,314 - 10.0.7.6 - INFO [Shibboleth-Audit.SSO:282] - 10.0.7.6||2021-02-01T05:51:53.314018Z||<a href="https://sts.windows.net">https://sts.windows.net</a>******/|_282b0ffa-9537-4b9c-9444-bbaf4bee7700|password|2021-02-01T04:42:10.204Z|azureObjectidentifier,azureIdentityprovider,azureGivenname,azureDisplayname,azureAuthnmethodsreferences,azureTenantid,azureEmailaddress,azureSurname|<a href="mailto:email@email.org">email@email.org</a>|emailAddress||false||Redirect|POST||Success|||Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.104 Safari/537.36<br>2021-02-01 11:21:53,388 - 10.0.7.6 - ERROR [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:78] - Profile Action SelectSubjectCanonicalizationFlow: No potential flows left to choose from, canonicalization will fail<br>2021-02-01 11:21:53,390 - 10.0.7.6 - INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:142] - Profile Action SelectAuthenticationFlow: Moving incomplete flow authn/SAML to intermediate set<br>2021-02-01 11:21:53,390 - 10.0.7.6 - INFO</span></i><span style='font-family:"Trebuchet MS",sans-serif'> [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] - Profile Action SelectAuthenticationFlow: No potential flows left to choose from, authentication failed<br> </span><o:p></o:p></p></div></div></div></div></body></html>