<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
We just want a user identifier from Azure. Here is relevant code:</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
attribute-resolver.xml:
<div> <AttributeDefinition xsi:type="SubjectDerivedAttribute"</div>
<div> forCanonicalization="true"</div>
<div> id="canonicalNameToUseForJoin"</div>
<div> principalAttributeName="azureName" /></div>
<div><br>
</div>
<div> <DataConnector id="passthroughAttributes" xsi:type="Subject"</div>
<div> exportAttributes="azureName" /></div>
<div><br>
</div>
<div>attribute-filter.xml:</div>
<div> <AttributeFilterPolicy id="FilterPolicyObject-Proxy-FromAzure-byIssuer-Type"></div>
<div> <PolicyRequirementRule xsi:type="Issuer" value="https://sts.windows.net/e202cd47-7a56-4baa-99e3-e3b71a7c77dd/" /></div>
<div> <AttributeRule attributeID="azureName"></div>
<div> <PermitValueRule xsi:type="ScopeMatchesShibMDScope" /></div>
<div> </AttributeRule></div>
<div> </AttributeFilterPolicy></div>
<div><br>
</div>
<div>azureClaims.xml:</div>
<div> <bean parent="shibboleth.TranscodingRuleLoader"></div>
<div> <constructor-arg></div>
<div> <list></div>
<div> <bean parent="shibboleth.TranscodingProperties"></div>
<div> <property name="properties"></div>
<div> <props merge="true"></div>
<div> <prop key="id">azureName</prop></div>
<div> <prop key="transcoder">SAML2ScopedStringTranscoder</prop></div>
<div> <prop key="saml2.name">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name</prop></div>
<div> <prop key="saml2.nameFormat">urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified</prop></div>
<div> <prop key="displayName.en">Name</prop></div>
<div> <prop key="description.en">Azure UPN of an account expected to be scoped thus transcoded that way</prop></div>
<div> </props></div>
<div> </property></div>
<div> </bean></div>
<div> </list></div>
<div> </constructor-arg></div>
<div> </bean></div>
<div><br>
</div>
<div>attribute-sourced-subject-c14n-config.xml:</div>
<div> <util:list id="shibboleth.c14n.attribute.AttributesToResolve"></div>
<div> <value>canonicalNameToUseForJoin</value></div>
<div> </util:list></div>
<div> <util:list id="shibboleth.c14n.attribute.AttributeSourceIds"></div>
<div> <value>canonicalNameToUseForJoin</value></div>
<div> </util:list></div>
<div><br>
</div>
<div>subject-c14n.xml:</div>
<div> <bean id="c14n/attribute" parent="shibboleth.PostLoginSubjectCanonicalizationFlow" /></div>
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div id="divtagdefaultwrapper" style="font-size:12pt; color:#000000; background-color:#FFFFFF; font-family:Calibri,Arial,Helvetica,sans-serif">
<div style="font-family:Tahoma; font-size:13px">---
<div><span id="ms-rterangepaste-start"></span><span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Roberto Ullfig - rullfig@uic.edu</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Systems Administrator</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">Enterprise Applications & Services | Technology Solutions</span><br style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">
<span style="font-family:arial,helvetica,sans-serif; font-size:13px; line-height:16.003px">University of Illinois - Chicago</span>
<div><span id="ms-rterangepaste-end"></span></div>
</div>
</div>
</div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott via users <users@shibboleth.net><br>
<b>Sent:</b> Tuesday, August 30, 2022 1:35 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Subject:</b> Re: Azure AD Connector from IDP v4.1 - canonicalization failure</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">More to the point, what is the actual goal here?<br>
<br>
If you're trying to just pass through a value from Azure, you're on 4.1 so you don't need to be running the resolver. The attribute-sourced method has properties in 4.1 that just directly pull in a decoded IdPAttribute from the IdP, and can disable running
the resolver at all. Much less confguration.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Crullfig%40uic.edu%7Cb667db1010f24e96011b08da8ab77e03%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637974817947249905%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=3pUSmv0yYqDbTaX6zMO6fOYE13lAOKTY5NzZMfh3tks%3D&reserved=0">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Crullfig%40uic.edu%7Cb667db1010f24e96011b08da8ab77e03%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637974817947249905%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=3pUSmv0yYqDbTaX6zMO6fOYE13lAOKTY5NzZMfh3tks%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>