<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Mark</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
It took some doing, but I got our IdP using AD for attributes - setting up the SAML-provided variable to map to the attribute resolver was fun, but it works.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I did all that in v4, and it survived the in-place upgrade to v5 smoothly.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Happy to go through my config next week and see what I've done (Jisc's guide on this is actually decent, I had a couple of issues where v4 config items were missing - a deployment I inherited).</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks<br>
Dave</div>
<div id="Signature" class="elementToProof">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);">
_________________________________________________</div>
<table style="border-collapse: collapse; border-spacing: 0px; box-sizing: border-box;">
<tbody>
<tr>
<td style="padding: 0cm 5.4pt; vertical-align: top; width: 303.75pt; height: 96.45pt;">
<p style="line-height: 120%; margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Arial, sans-serif; font-size: 10pt;"><b>Dave Perry</b></span><span style="font-family: "Times New Roman", serif; font-size: 12pt;"><br>
</span><span style="font-family: Arial, sans-serif; font-size: 9pt;">Application Analyst
<b>| </b>Innovation & Technology Services<br>
<br>
York St John University </span></p>
<p style="line-height: 120%; margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;">
<span style="font-family: Arial, sans-serif; font-size: 9pt;">Lord Mayor’s Walk, York, YO31 7EX<br>
T: +44(0)1904 876 0000<br>
</span><a href="mailto:d.perry1@yorksj.ac.uk" title="mailto:d.perry1@yorksj.ac.uk" style="margin-top: 0px; margin-bottom: 0px;">d.perry1@yorksj.ac.uk</a><span style="font-family: Arial, sans-serif; font-size: 9pt;">
<b>| </b><a href="http://www.yorksj.ac.uk/" style="margin-top: 0px; margin-bottom: 0px;">www.yorksj.ac.uk</a> </span></p>
</td>
</tr>
<tr>
<td style="padding: 0cm 5.4pt; vertical-align: top; width: 303.75pt; height: 74.7pt;">
<p style="margin: 0cm; font-family: Calibri, sans-serif; font-size: 11pt;"><span style="font-family: Arial, sans-serif; font-size: 12pt;"><b><img style="max-width: 100%; margin-top: 0px; margin-bottom: 0px;" data-outlook-trace="F:1|T:1" src="cid:a80532fa-8ef9-449d-b8a9-c8de32c25a5f"> </b></span></p>
</td>
</tr>
</tbody>
</table>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Mark Cairney via users <users@shibboleth.net><br>
<b>Sent:</b> Friday, October 11, 2024 3:48 PM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Mark Cairney <Mark.Cairney@ed.ac.uk><br>
<b>Subject:</b> Attribute Registry vs Attribute Resolver - best practice?</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.<br>
<br>
<br>
Hi,<br>
<br>
We're now looking at moving our IdP from being standalone (behind a<br>
REMOTE_USER variable for authentication) to using the new SAML proxy<br>
functionality provided in V4+.<br>
<br>
Having gone through the procedure on our Dev IdP it seems to me like<br>
using the attribute-registry.xml is the documented method for handling<br>
attributes coming upstream from Azure AD. [1],[2]<br>
<br>
To do this without changing how I handle the existing attributes getting<br>
looked up from LDAP I uncommented the<br>
'shibboleth.AttributeRegistryResources' block in services.xml but in<br>
attributes/default-rules.xml I've commented out everything except the<br>
new azureClaims.xml file e.g.<br>
<br>
<!-- Comment out everything but the additional azureClaims.xml --><br>
<br>
<!-- <import resource="inetOrgPerson.xml" /><br>
<import resource="eduPerson.xml" /><br>
<import resource="eduCourse.xml" /><br>
<import resource="samlSubject.xml" /> --><br>
<import resource="azureClaims.xml" /><br>
<br>
<br>
Is this a sensible approach for systems that have been upgraded from V3<br>
->V4 ->V5 and will there any issues going forward? My<br>
attribute-resolver.xml is relatively standard but does have some custom<br>
mappings for handing Windows-style claims (pre-Azure integration) and<br>
some mapped attributes for eduGAIN assurance purposes.<br>
<br>
<br>
[1]<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1467056889/Using+SAML+Proxying+in+the+V4+Shibboleth+IdP+to+connect+with+Azure+AD">https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FKB%2Fpages%2F1467056889%2FUsing%2BSAML%2BProxying%2Bin%2Bthe%2BV4%2BShibboleth%2BIdP%2Bto%2Bconnect%2Bwith%2BAzure%2BAD&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7C9ad5fdcb25ff4147099408dcea03e780%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638642549685756082%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=4x4J5X2YoLO5AR93Tqh%2FMUceKEydAEQravvhqbwHaa0%3D&reserved=0</a><br>
<br>
[2]<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/2783936889/SAML+Proxying+EntraID+Azure+with+the+Shibboleth+IdP">https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FKB%2Fpages%2F2783936889%2FSAML%2BProxying%2BEntraID%2BAzure%2Bwith%2Bthe%2BShibboleth%2BIdP&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7C9ad5fdcb25ff4147099408dcea03e780%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638642549685774974%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=yhFqsN9UPpsp75aOTv%2BjQGLcANbyggt1jIaeHs6yyIw%3D&reserved=0</a><br>
<br>
--<br>
/****************************<br>
<br>
Mark Cairney<br>
ITI Enterprise Services<br>
Information Services<br>
University of Edinburgh<br>
<br>
Tel: 0131 650 6565<br>
Email: Mark.Cairney@ed.ac.uk<br>
<br>
*******************************/<br>
<br>
The University of Edinburgh is a charitable body, registered in Scotland, with registration number SC005336.<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cd.perry1%40yorksj.ac.uk%7C9ad5fdcb25ff4147099408dcea03e780%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638642549685785850%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=HRsApxZ%2FozGyMdL7hvHUn5pZo3fcu7lmeuhC1K6QL2E%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>