<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Segoe UI";
        panose-1:2 11 5 2 4 2 4 2 2 3;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Although <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631686/ProfileConfiguration-SAML2SSO">
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631686/ProfileConfiguration-SAML2SSO</a> suggests that p:</span><span style="font-size:12.0pt;font-family:"Segoe UI",sans-serif;color:#172B4D;letter-spacing:-.05pt;background:white">authnContextComparison="exact"
 would work I just get </span><span style="mso-fareast-language:EN-US"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">2021-11-29 14:06:59,997 - 146.179.32.222 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:131] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching
 RelyingPartyContext based on SAML peer <a href="https://auth.surveys.evasysplus.co.uk/sp/shibboleth">
https://auth.surveys.evasysplus.co.uk/sp/shibboleth</a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">2021-11-29 14:06:59,997 - 146.179.32.222 - ERROR [net.shibboleth.idp.relyingparty.impl.ReloadingRelyingPartyConfigurationResolver:108] - RelyingPartyResolver 'shibboleth.RelyingPartyConfigurationResolver':
 error looking up Relying Party: Invalid configuration.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Aterea Brown<br>
<b>Sent:</b> 28 November 2021 20:19<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Changing IDP4 SAML Authentication RequestedAuthnContext Comparison value<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Segoe UI",sans-serif;color:black;background:white">Hi Neil,</span><span style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Segoe UI",sans-serif;color:black;background:white">Have you tried </span><span style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Segoe UI",sans-serif;color:black;background:white"><bean parent="SAML2.SSO"  p:</span><span style="font-size:12.0pt;font-family:"Segoe UI",sans-serif;color:#172B4D;letter-spacing:-.05pt;background:white">authnContextComparison="exact"</span><span style="font-family:"Segoe UI",sans-serif;color:black;background:white">></span><span style="font-size:12.0pt;color:black"><br>
</span><span style="font-family:"Segoe UI",sans-serif;color:black;background:white">        <property name="defaultAuthenticationMethods"></span><span style="font-family:"Segoe UI",sans-serif;color:black"><br>
<span style="background:white">                <list></span><br>
<span style="background:white">                        <bean parent="shibboleth.SAML2AuthnContextClassRef"</span><br>
<span style="background:white">                                c:classRef="urn:oasis:names:tc:SAML:2.0:ac:classes:Password" /></span><br>
<span style="background:white">                </list></span><br>
<span style="background:white">        </property></span><br>
<span style="background:white"></bean></span></span><span style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;color:black">in your relying-party.xml?<o:p></o:p></span></p>
</div>
<div id="Signature">
<div>
<div id="divtagdefaultwrapper">
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New";color:black">--<br>
Aterea Brown, AUT University<br>
Cybersecurity, ICT<br>
Email: <a href="mailto:atbrown@aut.ac.nz">atbrown@aut.ac.nz</a> Phone: 9219999 x 6523</span><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black"><o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="divRplyFwdMsg">
<p class="MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> on behalf of McLennan, Neil R <<a href="mailto:n.mclennan@imperial.ac.uk">n.mclennan@imperial.ac.uk</a>><br>
<b>Sent:</b> Saturday, 27 November 2021 2:12 AM<br>
<b>To:</b> 'Shib Users' <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Subject:</b> Changing IDP4 SAML Authentication RequestedAuthnContext Comparison value</span>
<o:p></o:p></p>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal">Has anybody worked out how to alter the RequestedAuthnContext for SAML authentication so that   <saml2p:RequestedAuthnContext Comparison="exact"> ?<br>
<br>
As per the useful <a href="https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FIDP4%2Fpages%2F1265631678%2FRelyingPartyConfiguration&amp;data=04%7C01%7Catbrown%40aut.ac.nz%7C90cddda4048244a638d108d9b0de7504%7C5e022ca15c044f878db7d588726274e3%7C1%7C0%7C637735292245553131%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;sdata=4f9NFeBFW8bEPhvaZu1Mw2WwncUzGeWI0S4p%2F0ErIZw%3D&amp;reserved=0">
https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FIDP4%2Fpages%2F1265631678%2FRelyingPartyConfiguration&amp;data=04%7C01%7Catbrown%40aut.ac.nz%7C90cddda4048244a638d108d9b0de7504%7C5e022ca15c044f878db7d588726274e3%7C1%7C0%7C637735292245553131%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;sdata=4f9NFeBFW8bEPhvaZu1Mw2WwncUzGeWI0S4p%2F0ErIZw%3D&amp;reserved=0</a>
 I have updated the relying party for the SAML authentication hoping it might override     <saml2p:RequestedAuthnContext Comparison="minimum"> however it remains the same<br>
<br>
Authentication request into Shibboleth<br>
<br>
    <saml2p:RequestedAuthnContext Comparison="minimum"><br>
        <saml2:AuthnContextClassRef xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef><br>
    </saml2p:RequestedAuthnContext><br>
<br>
Outgoing  Authentication  request from Shibboleth remains as <br>
<br>
    <saml2p:RequestedAuthnContext Comparison="minimum"><br>
        <saml2:AuthnContextClassRef xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef><br>
    </saml2p:RequestedAuthnContext><br>
<br>
What am I missing in the Relying Party configuration for SAML authentication? <br>
<br>
  <bean parent="RelyingPartyByName" c:relyingPartyIds="<a href="https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsts.windows.net%2Fxxxxxxxxxxxxxxx%2F&amp;data=04%7C01%7Catbrown%40aut.ac.nz%7C90cddda4048244a638d108d9b0de7504%7C5e022ca15c044f878db7d588726274e3%7C1%7C0%7C637735292245553131%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;sdata=jwoeFgEtcBpnd%2B%2Bwo3K0C0CUF%2BIn0YZWWIvhWffbcCo%3D&amp;reserved=0">https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsts.windows.net%2Fxxxxxxxxxxxxxxx%2F&amp;data=04%7C01%7Catbrown%40aut.ac.nz%7C90cddda4048244a638d108d9b0de7504%7C5e022ca15c044f878db7d588726274e3%7C1%7C0%7C637735292245553131%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;sdata=jwoeFgEtcBpnd%2B%2Bwo3K0C0CUF%2BIn0YZWWIvhWffbcCo%3D&amp;reserved=0</a>"><br>
          <property name="profileConfigurations"><br>
<list><br>
<bean parent="SAML2.SSO"  p:disallowedFeatures-ref="SAML2.SSO.FEATURE_AUTHNCONTEXT"><br>
        <property name="defaultAuthenticationMethods"><br>
                <list><br>
                        <bean parent="shibboleth.SAML2AuthnContextClassRef"<br>
                                c:classRef="urn:oasis:names:tc:SAML:2.0:ac:classes:Password" /><br>
                </list><br>
        </property><br>
</bean><br>
 </list><br>
            </property><br>
        </bean><br>
<br>
However <br>
<br>
Authentication request into Shibboleth<br>
<br>
    <saml2p:RequestedAuthnContext Comparison="minimum"><br>
        <saml2:AuthnContextClassRef xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef><br>
    </saml2p:RequestedAuthnContext><br>
<br>
Outgoing  Authentication  request from Shibboleth remains as <br>
<br>
    <saml2p:RequestedAuthnContext Comparison="minimum"><br>
        <saml2:AuthnContextClassRef xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef><br>
    </saml2p:RequestedAuthnContext><br>
<br>
Regards<br>
<br>
Neil McLennan<br>
-- <br>
For Consortium Member technical support, see <a href="https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&amp;data=04%7C01%7Catbrown%40aut.ac.nz%7C90cddda4048244a638d108d9b0de7504%7C5e022ca15c044f878db7d588726274e3%7C1%7C0%7C637735292245553131%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;sdata=sTWwy0Dyskka%2Bo7MFyFN74U59E4fZ9cBTy2DtwDxYXg%3D&amp;reserved=0">
https://apc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&amp;data=04%7C01%7Catbrown%40aut.ac.nz%7C90cddda4048244a638d108d9b0de7504%7C5e022ca15c044f878db7d588726274e3%7C1%7C0%7C637735292245553131%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&amp;sdata=sTWwy0Dyskka%2Bo7MFyFN74U59E4fZ9cBTy2DtwDxYXg%3D&amp;reserved=0</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</div>
</body>
</html>