<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Hello</p>
<p>in our federation we use "Supann" attributes, French extension to
eduPerson/SCHAC schema . <br>
</p>
<p><i><font size="2"><a class="moz-txt-link-freetext" href="https://services.renater.fr/documentation/supann/supann2021/recommandations/attributs/liste_des_attributs">https://services.renater.fr/documentation/supann/supann2021/recommandations/attributs/liste_des_attributs</a></font></i></p>
<p>I successfully enabled the resolution and sending (filter) from
our IDP v4 (cf<i><font size="2"> idp-process.log</font></i> below
[1] )<br>
</p>
<p><font size="2"><i>aacli </i></font>also shows correct
resolutions and values [2]</p>
<p>but on the SP side, I cannot get/map those added supann
attributes, only eduperson attributes shows up [3] <br>
</p>
<p>I declared the expected supann attributes in my SP3 in<i><font
size="2"> attribute-map.xml</font></i> , example here for <font
size="1"><i><font size="2">supannRessourceEtat </font></i><br>
</font></p>
<p> <font size="1"><Attribute
name="urn:oid:1.3.6.1.4.1.7135.1.2.1.55"
id="supannRessourceEtat"><br>
<AttributeDecoder xsi:type="StringAttributeDecoder"
caseSensitive="false"/><br>
</Attribute><br>
</font><br>
</p>
<p>On the IDP4 it is also declared in conf/attributes/supann.xml<br>
</p>
<p><i><font size="1"><bean
parent="shibboleth.TranscodingProperties"><br>
<property name="properties"><br>
<props merge="true"><br>
<prop
key="id">supannRessourceEtat</prop><br>
<prop
key="transcoder">SAML2StringTranscoder
SAML1StringTranscoder</prop><br>
<prop
key="saml2.name">urn:oid:1.3.6.1.4.1.7135.1.2.1.55</prop><br>
<prop
key="saml1.name">urn:renater:dir:attribute-def:supannRessourceEtat</prop><br>
<prop
key="displayName.en">supannRessourceEtat</prop><br>
<prop
key="displayName.de">supannRessourceEtat</prop><br>
<prop
key="displayName.fr">supannRessourceEtat</prop><br>
<prop
key="displayName.it">supannRessourceEtat</prop><br>
<prop key="description.en">Validity
state of a ressource or account</prop><br>
<prop key="description.fr">État de
validité d'une ressource ou d'un compte</prop><br>
</props><br>
</property><br>
</bean></font></i><br>
<br>
</p>
<p>according to the documentation:
<a class="moz-txt-link-freetext" href="https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065335311/AddAttribute">https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065335311/AddAttribute</a>
<br>
</p>
<p>I think I did everything necessary , except perhaps a pb of
AttributeNamespace or Decoder ?, and/or the fact that it is a
multivalued attribute ? <br>
</p>
<p>I also set <i><font size="2">log4j.rootCategory=DEBUG</font></i>
in shibd.logger , but perhaps there is other subcategories to add
debug to in order the debug attribute mapping problems ? <br>
</p>
<p>Please let me know what else can I do in order to map this
attribute.<br>
</p>
<p>Regards <br>
</p>
<p>[1]<br>
</p>
<p><i><font size="1">procaccia|<a class="moz-txt-link-freetext" href="https://fres.tsp.eu/sp|_6cd1b6bdeb39bd81b1e71992fadddb4f|password|2023-01-11T22:04:19.818128Z|">https://fres.tsp.eu/sp|_6cd1b6bdeb39bd81b1e71992fadddb4f|password|2023-01-11T22:04:19.818128Z|</a></font></i></p>
<p><i><font size="1"><font size="2"><b>supannEntiteAffectation</b></font>,mail,eduPersonAffiliation,displayName,givenName,eduPersonPrincipalName,sn,<font
size="2"><b>supannAutreMail,supannRessourceEtat</b></font>|</font></i></p>
<p><i><font size="1">AAdzZWNyZXQx6+LtDNZSaSWPOiwPHg7A8TvwnZB2/7+yUswh/72....9vaRIEvgCk=|transient|false|false||Redirect|POST||Success|</font></i></p>
<p><i><font size="1">|994879436....360|Mozilla/5.0 (X11; Linux
x86_64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/106.0.0.0 Safari/537.36</font></i></p>
<p><br>
</p>
<p>[2] <i><font size="1"><br>
</font></i></p>
<p><font size="1"><i>[root@idp4 shibboleth-idp]# ./bin/aacli.sh
--requester=<a class="moz-txt-link-freetext" href="https://fres.tsp.eu/sp">https://fres.tsp.eu/sp</a> --configDir=conf/
--principal=procaccia</i></font><br>
<font size="1">{<br>
"name": "supannRessourceEtat",<br>
"values": [<br>
"{REST}A:Premium",<br>
"{TR}A:SupannActif",<br>
"{ECAMPUS}A:SupannActif",<br>
</font></p>
<p><br>
</p>
<p>[3]</p>
<p><i><font size="1">2023-01-11 23:04:23 DEBUG
Shibboleth.AttributeFilter [2] [default]: filtering 6
attribute(s) from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
[default]: applying filtering rule(s) for attribute
(givenName) from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
[default]: applying filtering rule(s) for attribute
(displayName) from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
[default]: applying filtering rule(s) for attribute (mail)
from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
[default]: applying filtering rule(s) for attribute
(unscoped-affiliation) from
(<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
[default]: applying filtering rule(s) for attribute (eppn)
from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
[default]: applying filtering rule(s) for attribute (sn) from
(<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
2023-01-11 23:04:23 DEBUG Shibboleth.SessionCache [2]
[default]: creating new session</font></i><br>
<br>
</p>
</body>
</html>