<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Hello</p>
    <p>in our federation we use "Supann" attributes, French extension to
      eduPerson/SCHAC schema . <br>
    </p>
    <p><i><font size="2"><a class="moz-txt-link-freetext" href="https://services.renater.fr/documentation/supann/supann2021/recommandations/attributs/liste_des_attributs">https://services.renater.fr/documentation/supann/supann2021/recommandations/attributs/liste_des_attributs</a></font></i></p>
    <p>I successfully enabled the resolution and sending (filter) from
      our IDP v4 (cf<i><font size="2"> idp-process.log</font></i> below
      [1] )<br>
    </p>
    <p><font size="2"><i>aacli </i></font>also shows correct
      resolutions and values [2]</p>
    <p>but on the SP side, I cannot get/map those added supann
      attributes, only eduperson attributes shows up [3]  <br>
    </p>
    <p>I declared the expected supann attributes in my SP3 in<i><font
          size="2"> attribute-map.xml</font></i> , example here for <font
        size="1"><i><font size="2">supannRessourceEtat </font></i><br>
      </font></p>
    <p> <font size="1"><Attribute
        name="urn:oid:1.3.6.1.4.1.7135.1.2.1.55"
        id="supannRessourceEtat"><br>
                <AttributeDecoder xsi:type="StringAttributeDecoder"
        caseSensitive="false"/><br>
            </Attribute><br>
      </font><br>
    </p>
    <p>On the IDP4 it is also declared in conf/attributes/supann.xml<br>
    </p>
    <p><i><font size="1"><bean
          parent="shibboleth.TranscodingProperties"><br>
                      <property name="properties"><br>
                          <props merge="true"><br>
                              <prop
          key="id">supannRessourceEtat</prop><br>
                              <prop
          key="transcoder">SAML2StringTranscoder
          SAML1StringTranscoder</prop><br>
                              <prop
          key="saml2.name">urn:oid:1.3.6.1.4.1.7135.1.2.1.55</prop><br>
                              <prop
key="saml1.name">urn:renater:dir:attribute-def:supannRessourceEtat</prop><br>
                              <prop
          key="displayName.en">supannRessourceEtat</prop><br>
                              <prop
          key="displayName.de">supannRessourceEtat</prop><br>
                              <prop
          key="displayName.fr">supannRessourceEtat</prop><br>
                              <prop
          key="displayName.it">supannRessourceEtat</prop><br>
                              <prop key="description.en">Validity
          state of a ressource or account</prop><br>
                              <prop key="description.fr">État de
          validité d'une ressource ou d'un compte</prop><br>
                          </props><br>
                      </property><br>
                  </bean></font></i><br>
      <br>
    </p>
    <p>according to the documentation: 
<a class="moz-txt-link-freetext" href="https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065335311/AddAttribute">https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065335311/AddAttribute</a>
      <br>
    </p>
    <p>I think I did everything necessary , except perhaps a pb of
      AttributeNamespace or Decoder ?, and/or the fact that it is a
      multivalued attribute ? <br>
    </p>
    <p>I also set <i><font size="2">log4j.rootCategory=DEBUG</font></i>
      in shibd.logger , but perhaps there is other subcategories to add
      debug to in order the debug attribute mapping problems ? <br>
    </p>
    <p>Please let me know what else can I do in order to map this
      attribute.<br>
    </p>
    <p>Regards <br>
    </p>
    <p>[1]<br>
    </p>
    <p><i><font size="1">procaccia|<a class="moz-txt-link-freetext" href="https://fres.tsp.eu/sp|_6cd1b6bdeb39bd81b1e71992fadddb4f|password|2023-01-11T22:04:19.818128Z|">https://fres.tsp.eu/sp|_6cd1b6bdeb39bd81b1e71992fadddb4f|password|2023-01-11T22:04:19.818128Z|</a></font></i></p>
    <p><i><font size="1"><font size="2"><b>supannEntiteAffectation</b></font>,mail,eduPersonAffiliation,displayName,givenName,eduPersonPrincipalName,sn,<font
            size="2"><b>supannAutreMail,supannRessourceEtat</b></font>|</font></i></p>
    <p><i><font size="1">AAdzZWNyZXQx6+LtDNZSaSWPOiwPHg7A8TvwnZB2/7+yUswh/72....9vaRIEvgCk=|transient|false|false||Redirect|POST||Success|</font></i></p>
    <p><i><font size="1">|994879436....360|Mozilla/5.0 (X11; Linux
          x86_64) AppleWebKit/537.36 (KHTML, like Gecko)
          Chrome/106.0.0.0 Safari/537.36</font></i></p>
    <p><br>
    </p>
    <p>[2] <i><font size="1"><br>
        </font></i></p>
    <p><font size="1"><i>[root@idp4 shibboleth-idp]# ./bin/aacli.sh
          --requester=<a class="moz-txt-link-freetext" href="https://fres.tsp.eu/sp">https://fres.tsp.eu/sp</a> --configDir=conf/
          --principal=procaccia</i></font><br>
      <font size="1">{<br>
            "name": "supannRessourceEtat",<br>
            "values": [<br>
                "{REST}A:Premium",<br>
                "{TR}A:SupannActif",<br>
                "{ECAMPUS}A:SupannActif",<br>
      </font></p>
    <p><br>
    </p>
    <p>[3]</p>
    <p><i><font size="1">2023-01-11 23:04:23 DEBUG
          Shibboleth.AttributeFilter [2] [default]: filtering 6
          attribute(s) from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
          2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
          [default]: applying filtering rule(s) for attribute
          (givenName) from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
          2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
          [default]: applying filtering rule(s) for attribute
          (displayName) from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
          2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
          [default]: applying filtering rule(s) for attribute (mail)
          from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
          2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
          [default]: applying filtering rule(s) for attribute
          (unscoped-affiliation) from
          (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
          2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
          [default]: applying filtering rule(s) for attribute (eppn)
          from (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
          2023-01-11 23:04:23 DEBUG Shibboleth.AttributeFilter [2]
          [default]: applying filtering rule(s) for attribute (sn) from
          (<a class="moz-txt-link-freetext" href="https://idp4.tsp.eu/idp/shibboleth">https://idp4.tsp.eu/idp/shibboleth</a>)<br>
          2023-01-11 23:04:23 DEBUG Shibboleth.SessionCache [2]
          [default]: creating new session</font></i><br>
      <br>
    </p>
  </body>
</html>