<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-ligatures:standardcontextual;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0cm;
        margin-right:0cm;
        margin-bottom:0cm;
        margin-left:36.0pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-ligatures:standardcontextual;
        mso-fareast-language:EN-US;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:1282417595;
        mso-list-type:hybrid;
        mso-list-template-ids:585120866 1684565960 134807555 134807557 134807553 134807555 134807557 134807553 134807555 134807557;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:-;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-font-family:Calibri;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:"Courier New";}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:"Courier New";}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:"Courier New";}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;
        font-family:Wingdings;}
ol
        {margin-bottom:0cm;}
ul
        {margin-bottom:0cm;}
--></style>
</head>
<body lang="en-AT" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span lang="DE-AT">dear list, <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="DE-AT"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="DE-AT">following setting: shibboleth 4.3.1 + oidc 3.4.0 plugin<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">using saml proxy for authentication to an saml-upstream-idp<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">some attributes are subject derived from the upstream IDP, authorization code flow design<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">on an oidc based sp logon it performs as follows:<o:p></o:p></span></p>
<ul style="margin-top:0cm" type="disc">
<li class="MsoListParagraph" style="margin-left:0cm;mso-list:l0 level1 lfo1"><span lang="EN-US">saml proxy authentication<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:0cm;mso-list:l0 level1 lfo1"><span lang="EN-US">oidc authorization works, attributes being resolved, subject canonicalization works, all upstream subject derived attributes resolved (though not needed in that
 step)<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:0cm;mso-list:l0 level1 lfo1"><span lang="EN-US">rp now issues token request with accesstoken/authorization code flow (from server, not from client any more, in own session)<o:p></o:p></span></li><ul style="margin-top:0cm" type="circle">
<li class="MsoListParagraph" style="margin-left:0cm;mso-list:l0 level2 lfo1"><span lang="EN-US">attributes are being resolved again, which works for all local available attributes<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:0cm;mso-list:l0 level2 lfo1"><span lang="EN-US">upstream subject is now not available, possibly because the subject from the upstream is contained in the user session and not related to the access token?<o:p></o:p></span></li><li class="MsoListParagraph" style="margin-left:0cm;mso-list:l0 level2 lfo1"><span lang="EN-US">So subject derived attributes cannot be resolved.
<o:p></o:p></span></li></ul>
<li class="MsoListParagraph" style="margin-left:0cm;mso-list:l0 level1 lfo1"><span lang="EN-US">though the upstream subject is still available (but I suspect in the user session from authorization, not in the Server-to-Application TokenResponse Session)<o:p></o:p></span></li></ul>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">any ideas how to solve that? <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">best regards, <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">Martin<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">## Token Request which does not find Subject<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,568 - x.x.x.252- DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractInitializeOutboundResponseMessageContext:69] - Profile Action InitializeOutboundTokenResponseMessageContext: Initialized
 outbound message context<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,570 - x.x.x.252- DEBUG [PROTOCOL_MESSAGE.OAUTH2:77] - OIDCTokenRequestDecoder{authorizationGrant=AuthorizationCodeGrant{authorizationCode=***,
<a href="mailto:codeVerifier=com.nimbusds.oauth2.sdk.pkce.CodeVerifier@1f76d5cf">
codeVerifier=com.nimbusds.oauth2.sdk.pkce.CodeVerifier@1f76d5cf</a>, redirectionURI=***, type=authorization_code}, clientAuthentication=ClientAuthentication{clientId=***, method=client_secret_basic}, customParameters={}, endpointURI=https://127.0.0.1:8080/idp/profile/oidc/token}<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,571 - x.x.x.252- DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler'
 on INBOUND message context<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,571 - x.x.x.252- DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message
 of type 'com.nimbusds.oauth2.sdk.TokenRequest'<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,571 - x.x.x.252- DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler:121] - Message Handler:  net.shibboleth.oidc.metadata.context.OIDCMetadataContext added to MessageContext
 as child of org.opensaml.messaging.context.MessageContext<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,571 - x.x.x.252- DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeRelyingPartyContext:162] - Attaching RelyingPartyContext for ***<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,571 - x.x.x.252- DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeRelyingPartyContext:168] - Profile Action InitializeRelyingPartyContext: Setting the rp context verified<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,571 - x.x.x.252- DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:253] - Resolving relying party configuration<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,573 - x.x.x.252- DEBUG [net.shibboleth.idp.profile.impl.SelectRelyingPartyConfiguration:174] - Profile Action SelectRelyingPartyConfiguration: Found relying party configuration shibboleth.DefaultRelyingParty
 for request<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,573 - x.x.x.252- DEBUG [net.shibboleth.idp.profile.interceptor.impl.PopulateProfileInterceptorContext:147] - Profile Action PopulateProfileInterceptorContext: No inbound interceptor flows active for
 this request<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,574 - x.x.x.252- DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:222] - Profile Action InitializeAuthenticationContext: Created authentication context: AuthenticationContext{initiationInstant=2023-06-13T13:34:04.573998Z,
 isPassive=false, forceAuthn=false, requiredName=null, hintedName=null, maxAge=null, potentialFlows=[], activeResults=[], attemptedFlow=null, signaledFlowId=null, authenticationStateMap={}, resultCacheable=true, authenticationResult=null, completionInstant=null}<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,575 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:213] - Profile Action PopulateAuthenticationContext: Installed 1 potential authentication flows into AuthenticationContext<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,575 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.InitializeRequestedPrincipalContext:152] - Profile Action InitializeRequestedPrincipalContext: Profile configuration did not supply any default
 authentication methods<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,575 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:57] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,575 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:76] - Profile Action FilterFlowsByNonBrowserSupport: Retaining flow authn/OAuth2Client, it supports non-browser
 authentication<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,575 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:88] - Profile Action FilterFlowsByNonBrowserSupport: Potential authentication flows left after filtering: [authn/OAuth2Client]<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,576 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:274] - Profile Action SelectAuthenticationFlow: No specific Principals requested<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,576 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:312] - Profile Action SelectAuthenticationFlow: No usable active results available, selecting an inactive flow<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,576 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:369] - Profile Action SelectAuthenticationFlow: Selecting inactive authentication flow authn/OAuth2Client<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,582 - x.x.x.252- DEBUG [net.shibboleth.idp.plugin.oidc.op.authn.impl.OIDCClientInfoCredentialValidator:143] - Credential Validator oauth2-clientinfo: Attempting to authenticate effective client ID
 ***<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,583 - x.x.x.252- INFO [net.shibboleth.idp.plugin.oidc.op.authn.impl.OIDCClientInfoCredentialValidator:152] - Credential Validator oauth2-clientinfo: Login by *** succeeded<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,583 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.AbstractValidationAction:398] - Profile Action ValidateCredentials: Adding custom Principal(s) defined on underlying flow descriptor<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,583 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.PopulateSubjectCanonicalizationContext:75] - Profile Action PopulateSubjectCanonicalizationContext: Installing 3 canonicalization flows into SubjectCanonicalizationContext<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,584 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:100] - Profile Action SelectSubjectCanonicalizationFlow: Checking canonicalization flow c14n/attribute for applicability...<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,584 - x.x.x.252- DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:83] - Profile Action SelectSubjectCanonicalizationFlow: Selecting canonicalization flow c14n/attribute<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,585 - x.x.x.252- DEBUG [net.shibboleth.idp.attribute.resolver.impl.AttributeResolverImpl:251] - Attribute Resolver 'ShibbolethAttributeResolver': Initiating attribute resolution with label: c14n/attribute<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,585 - x.x.x.252- DEBUG [net.shibboleth.idp.attribute.resolver.impl.AttributeResolverImpl:280] - Attribute Resolver 'ShibbolethAttributeResolver': Attempting to resolve the following attribute definitions
 [canonicalUsername]<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,585 - x.x.x.252- DEBUG [net.shibboleth.idp.attribute.resolver.impl.AttributeResolverImpl:469] - Attribute Resolver 'ShibbolethAttributeResolver': Resolving dependencies for 'canonicalUsername'<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,585 - x.x.x.252- DEBUG [net.shibboleth.idp.attribute.resolver.impl.AttributeResolverImpl:478] - Attribute Resolver 'ShibbolethAttributeResolver': Finished resolving dependencies for 'canonicalUsername'<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">2023-06-13 15:34:04,585 - x.x.x.252- INFO [net.shibboleth.idp.attribute.resolver.ad.impl.ContextDerivedAttributeDefinition:176] - SubjectDerivedAttributeDefinition canonicalUsername Generated no values, no attribute resolved
<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
</div>
</body>
</html>