<div dir="ltr">>I didn't have an attribute-sourced-subject...xml file in my installation (based on 4.2.1). But just copy/pasting the 6 or 8 lines for it, from the cookbook, caused errors.<div><br></div><div>I had started SAML proxying with 4.0 and originally had attribute-sourced-subject-c14n-config.xml in my config. When I upgraded to 4.1, I removed the .xml file and updated subject-c14n.properties. I don't think adding the .xml file will help.</div><div><br></div><div>> even though the AttributeDefinition needed, DataConnector needed, and filter policy needed are there</div><div><br></div><div>How about the transcoding, which gets the attribute in the claim and puts it into a form the IdP can use. This is the "Proxy Task 3. Enable IdP to Recognize Azure AD Claims" section. I only use one attribute from Google, so my conf/attributes/googleSAMLproxy.xml is a bit simpler than the example.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Apr 17, 2023 at 6:12 PM Dave Perry via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
Thanks Tony</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0);background-color:rgb(255,255,255)">
<div><br>
</div>
<div>I didn't have an attribute-sourced-subject...xml file in my installation (based on 4.2.1). But just copy/pasting the 6 or 8 lines for it, from the cookbook, caused errors.</div>
<div><br>
</div>
Moving to the 4.1 way as you described (including having to delete the file named above), seems to not be picking up the canonicalNameToUseForJoin Id. So it is not able to complete the c14/attribute flow, and the logs are saying 'DataConnector passthroughAttributes
produced the following 0 attributes during resolution: []' - even though the AttributeDefinition needed, DataConnector needed, and filter policy needed are there in the appropriate config files.</div>
<div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
azureName is definitely being detected according to the logs file.</div>
<div id="m_-3525191086978221189m_-2571858971232514346m_4668455568955049149m_-2343064313061321964Signature">
<div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span style="font-size:10pt">_________________________________________________</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span style="font-size:10pt"></span></div>
<table style="border-collapse:collapse;border:none">
<tbody>
<tr style="height:96.45pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt;height:96.45pt">
<p style="margin:0cm;line-height:120%;font-size:11pt;font-family:Calibri,sans-serif">
<a><b><span style="font-size:10pt;font-family:Arial,sans-serif">Dave Perry</span></b></a><span><span style="font-size:12pt;font-family:"Times New Roman",serif"><br>
</span></span><span><span style="font-size:9pt;font-family:Arial,sans-serif">Application Analyst<span> </span><b>|<span>
</span></b>Innovation & Technology Services<br>
<br>
</span></span><span><span style="font-size:9pt;font-family:Arial,sans-serif">York St John University<u></u> <u></u></span></span></p>
<p style="margin:0cm;line-height:120%;font-size:11pt;font-family:Calibri,sans-serif">
<span><span style="font-size:9pt;font-family:Arial,sans-serif">Lord Mayor’s Walk, York, YO31 7EX</span></span><span><span style="font-size:9pt;font-family:Arial,sans-serif"><br>
T: +44(0)1904 876 0000<br>
</span></span><a href="mailto:email@yorksj.ac.uk" target="_blank"><span><span style="font-size:9pt;font-family:Arial,sans-serif">email@yorksj.ac.uk</span></span></a><span><span style="font-size:9pt;font-family:Arial,sans-serif"><span>
</span><b>|<span> </span></b></span></span><a href="http://www.yorksj.ac.uk/" target="_blank"><span><span style="font-size:9pt;font-family:Arial,sans-serif">www.y</span></span><span><span style="font-size:9pt;font-family:Arial,sans-serif">orksj</span></span><span><span style="font-size:9pt;font-family:Arial,sans-serif">.ac.uk</span></span></a><span style="font-size:9pt;font-family:Arial,sans-serif"><u></u> <u></u></span></p>
</td>
</tr>
<tr style="height:74.7pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt;height:74.7pt">
<p style="margin:0cm;font-size:11pt;font-family:Calibri,sans-serif">
<b><span style="font-size:12pt;font-family:Arial,sans-serif"><u></u><img style="max-width: 100%;" src="cid:18795afe72043ec65091"> <u></u></span></b></p>
</td>
</tr>
</tbody>
</table>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span style="font-size:10pt"></span></div>
</div>
</div>
</div>
<div id="m_-3525191086978221189m_-2571858971232514346m_4668455568955049149m_-2343064313061321964appendonsend"></div>
<hr style="display:inline-block;width:98%">
<div id="m_-3525191086978221189m_-2571858971232514346m_4668455568955049149m_-2343064313061321964divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
<b>Sent:</b> 17 April 2023 23:56<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Cc:</b> Dave Perry <<a href="mailto:d.perry1@yorksj.ac.uk" target="_blank">d.perry1@yorksj.ac.uk</a>><br>
<b>Subject:</b> Re: SAML proxy of IdP to Azure - c14 + requester questions</font>
<div> </div>
</div>
<div><font size="2"><span style="font-size:11pt">
<div>Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.<br>
<br>
<br>
> Noting that it says the document hasn't been updated for v4.1+<br>
<br>
That's why you should use the documentation itself.<br>
<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1282539600/SAMLAuthnConfiguration" target="_blank">https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FIDP4%2Fpages%2F1282539600%2FSAMLAuthnConfiguration&data=05%7C01%7Cd.perry1%40yorksj.ac.uk%7C0ea6c048644442d6fade08db3f96efd6%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638173689742228698%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=b3EBHYEbsQbIx4OwqRba%2FgFnRoUe2CFxuhzLxUh5hIA%3D&reserved=0</a><br>
<br>
It's covered there.<br>
<br>
> When checking the process log, as it checks against each Attribute Filter, it is showing a<br>
> request value of the IdP's entityID.<br>
<br>
Yes. The SP in that step is the "IdP" (your IdP). The IdP is Azure. So the requester is you and the issuer is the Azure entityID. That's inbound filtering, and is covered in the documentation.<br>
<br>
> I'm not clear why it has seemingly 'lost' the original resource URL requested<br>
<br>
The original resource URL is in no way ever known, that's not part of SAML. If your attribute acceptance inbound depends on the identity of the original SP (not the URL), then that is possible to build rules against that via the ProxiedRequester matchers, but
generally it doesn't, it's normally just based on the issuer, and there are full set of rules included for that.<br>
<br>
-- Scott<br>
<br>
<br>
</div>
</span></font></div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></blockquote></div><br clear="all"><div><br></div><span>-- </span><br><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><b>Tony Skalski (he/him/his)</b></div><div dir="ltr">System Administrator | IT</div><div dir="ltr">Office:<b> </b><a href="tel:(507)786-3227" target="_blank">507-786-3227</a><br></div><div dir="ltr">1510 St. Olaf Avenue Northfield, MN 55057</div><div dir="ltr"><a href="http://stolaf.edu" target="_blank">stolaf.edu</a></div><div><div><br><br></div></div></div></div></div></div></div></div></div></div>