<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000"><div id="zimbraEditorContainer" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000" class="8"><div>I did restarted shibd<br>for the second most obvious pb, perhaps the IDP finally doesn't sent the attributes, although I did restarted tomcat, and in idp-process.log [1]  I do see the attribute beeing mentioned (and it does resolves with aacli )  </div><div>I am lost, where should I try to resolve this problem, on the IDP side and/or SP side ? my supann* attributes seems to get lost in between <br></div><div><br data-mce-bogus="1"></div><div>[1] ID process log , attribute are there (in bold), so for me IDP is not the pb  <br><br><span style="font-size: 11pt;" data-mce-style="font-size: 11pt;"><em>https://fres.tsp.eu/sp|AttributeReleaseConsent|procacci|mail||true</em></span><br><span style="font-size: 11pt;" data-mce-style="font-size: 11pt;"><em>2023-01-13 19:46:24,181 - 157.159.52.132 - INFO [Shibboleth-Audit.SSO:283] - 152.157.52.12|2023-01-13T18:45:51.022299Z|2023-01-13T18:46:24.181871Z|procacci|https://fres.tsp.eu/shibboleth|_9cac...7a9|password|2023-01-13T18:46:09.145114Z|<strong>supannEntiteAffectation</strong>,mail,eduPersonAffiliation,displayName,givenName,eduPersonPrincipalName,sn,<strong>supannAutreMai</strong>l,<strong>supannRessourceEtat|</strong></em></span><br></div><div><br data-mce-bogus="1"></div><div>[2] on the shibd/SP side, shid.log in debug mode, doesn't show the supann* attributes in the saml assertion, but do show 2 <span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em><strong> unable to extract attributes, unknown XML object type: saml2p:Response</strong></em></span> cf below<br></div><br data-mce-bogus="1"><div><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em> <saml2:AttributeStatement><saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>PROCACCIA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>procaccia@tsp.eu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>member</saml2:AttributeValue><saml2:AttributeValue>employee</saml2:AttributeValue><saml2:AttributeValue>staff</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>jehan.procaccia@tsp.eu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Jehan PROCACCIA</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Jehan</saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion></saml2p:Response></em></span><br></div><div><br data-mce-bogus="1"></div><div>....<br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><div><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG XMLTooling.Signature [2] [default]: unmarshalling ds:Signature</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: extracting issuer from SAML 2.0 protocol message</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: message from (https://idp4.tsp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: searching metadata for message issuer...</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: recovered request/response correlation value (_140309e48ee414a6e0a701a660aa17cf)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: evaluating message flow policy (correlation off, replay checking on, expiration 60)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: ignoring InResponseTo, correlation checking is disabled</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG XMLTooling.StorageService [2] [default]: inserted record (_67c81fd930ad5583b696d618d392d035) in context (MessageFlow) with expiration (1673635824)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [2] [default]: validating signature profile</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG XMLTooling.CredentialCriteria [2] [default]: keys didn't match</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG XMLTooling.TrustEngine.ExplicitKey [2] [default]: attempting to validate signature with the peer's credentials</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG XMLTooling.TrustEngine.ExplicitKey [2] [default]: signature validated with credential</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [2] [default]: signature verified against message issuer</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.SSO.SAML2 [2] [default]: processing message against SAML 2.0 SSO profile</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.SSO.SAML2 [2] [default]: extracting issuer from SAML 2.0 assertion</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: evaluating message flow policy (correlation off, replay checking on, expiration 60)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: ignoring InResponseTo, correlation checking is disabled</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG XMLTooling.StorageService [2] [default]: inserted record (_9cac9d8e377ba2aee7914847b79117a9) in context (MessageFlow) with expiration (1673635824)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2] [default]: ignoring InResponseTo, correlation checking is disabled</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2] [default]: assertion satisfied bearer confirmation requirements</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.SSO.SAML2 [2] [default]: SSO profile processing completed successfully</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.SSO.SAML2 [2] [default]: extracting pushed attributes...</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeExtractor.XML [2] [default]:<strong> unable to extract attributes, unknown XML object type: saml2p:Response</strong></em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeExtractor.XML [2] [default]: skipping NameID with format (urn:oasis:names:tc:SAML:2.0:nameid-format:transient)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeExtractor.XML [2] [default]:<strong> unable to extract attributes, unknown XML object type: saml2:AuthnStatement</strong></em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeDecoder.String [2] [default]: decoding SimpleAttribute (sn) from SAML 2 Attribute (urn:oid:2.5.4.4) with 1 value(s)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeDecoder.Scoped [2] [default]: decoding ScopedAttribute (eppn) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.6) with 1 value(s)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeDecoder.String [2] [default]: decoding SimpleAttribute (unscoped-affiliation) from SAML 2 Attribute (urn:oid:1.3.6.1.4.1.5923.1.1.1.1) with 3 value(s)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeDecoder.String [2] [default]: decoding SimpleAttribute (mail) from SAML 2 Attribute (urn:oid:0.9.2342.19200300.100.1.3) with 1 value(s)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeDecoder.String [2] [default]: decoding SimpleAttribute (displayName) from SAML 2 Attribute (urn:oid:2.16.840.1.113730.3.1.241) with 1 value(s)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeDecoder.String [2] [default]: decoding SimpleAttribute (givenName) from SAML 2 Attribute (urn:oid:2.5.4.42) with 1 value(s)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeFilter [2] [default]: filtering 6 attribute(s) from (https://idp4.tsp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeFilter [2] [default]: applying filtering rule(s) for attribute (givenName) from (https://idp4.tsp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeFilter [2] [default]: applying filtering rule(s) for attribute (displayName) from (https://idp4.tsp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeFilter [2] [default]: applying filtering rule(s) for attribute (mail) from (https://idp4.tsp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeFilter [2] [default]: applying filtering rule(s) for attribute (unscoped-affiliation) from (https://idp4.tsp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeFilter [2] [default]: applying filtering rule(s) for attribute (eppn) from (https://idp4.sp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.AttributeFilter [2] [default]: applying filtering rule(s) for attribute (sn) from (https://idp4.tsp.eu/idp/shibboleth)</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.SessionCache [2] [default]: creating new session</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG Shibboleth.SessionCache [2] [default]: storing new session...</em></span><br><span style="font-size: 10pt;" data-mce-style="font-size: 10pt;"><em>2023-01-13 19:46:24 DEBUG XMLTooling.StorageService [2] [default]: inserted record (session) in context (_0ac069</em></span><em>...567)</em><br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><br><br><hr id="zwchr" data-marker="__DIVIDER__"><div data-marker="__HEADERS__"><b>De: </b>"Cantor, Scott via users" <users@shibboleth.net><br><b>À: </b>"Shib Users" <users@shibboleth.net><br><b>Cc: </b>"Scott Cantor" <cantor.2@osu.edu><br><b>Envoyé: </b>Vendredi 13 Janvier 2023 13:59:32<br><b>Objet: </b>Re: Add attributes map to SP3 (supann)<br></div><br><div data-marker="__QUOTED_TEXT__">The most obvious problem would be not restarting shibd, and the second most obvious is that it's not even there and the IdP registry service wasn't reloaded.<br><br>-- Scott<br><br><br><br>-- <br>For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div></div><br></div></body></html>