<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Latha;
panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;
mso-ligatures:none;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-IN" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Hi Team,<br>
<br>
Kindly let us know for any updates on our below request, otherwise please let us know for more details.<br>
<br>
Awaiting your response<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Thanks and Regards<br>
Kalidasan S<br>
Advisory - Senior Solution Advisor<br>
</span><span lang="EN-US" style="mso-ligatures:none">Cyber IAM(Okta) | Deloitte US India Risk and Financial Advisory<o:p></o:p></span></p>
<p class="MsoNormal"><a href="mailto:kalids@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">kalids@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none"> |
</span><a href="http://www.deloitte.com/"><span lang="EN-US" style="mso-ligatures:none">www.deloitte.com</span></a><span style="mso-fareast-language:EN-US"><o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span lang="EN-US" style="mso-ligatures:none">From:</span></b><span lang="EN-US" style="mso-ligatures:none"> Gangadharappa, Gautham <ggangadharappa@deloitte.com>
<br>
<b>Sent:</b> Saturday, November 2, 2024 1:33 AM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Cc:</b> Kodali, Venkatappaiah <vkodali@deloitte.com>; Cherukuri, Bhanu Teja <bcherukuri@deloitte.com>; Bhruguwar, Vinay Mahendra <vbhruguwar@deloitte.com>; Jehng, Connie <cjehng@deloitte.com>; S, Kalidasan <kalids@deloitte.com>; Gangadharappa, Gautham <ggangadharappa@deloitte.com><br>
<b>Subject:</b> RE: Request for SAML attributes mapping configuration between Okta to Shibboleth IDP<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span lang="EN-US">Is there any update on the question below?<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-ligatures:none">Thanks, <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="mso-ligatures:none">Gautham<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span lang="EN-US" style="mso-ligatures:none">From:</span></b><span lang="EN-US" style="mso-ligatures:none"> S, Kalidasan <</span><a href="mailto:kalids@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">kalids@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none">>
<br>
<b>Sent:</b> Wednesday, October 30, 2024 1:10 PM<br>
<b>To:</b> </span><a href="mailto:users@shibboleth.net"><span lang="EN-US" style="mso-ligatures:none">users@shibboleth.net</span></a><span lang="EN-US" style="mso-ligatures:none"><br>
<b>Cc:</b> Kodali, Venkatappaiah <</span><a href="mailto:vkodali@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">vkodali@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none">>; Cherukuri, Bhanu Teja <</span><a href="mailto:bcherukuri@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">bcherukuri@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none">>;
Gangadharappa, Gautham <</span><a href="mailto:ggangadharappa@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">ggangadharappa@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none">>; Bhruguwar, Vinay Mahendra <</span><a href="mailto:vbhruguwar@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">vbhruguwar@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none">>;
Jehng, Connie <</span><a href="mailto:cjehng@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">cjehng@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none">><br>
<b>Subject:</b> Request for SAML attributes mapping configuration between Okta to Shibboleth IDP<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal">Hi Team,<br>
<br>
As part of our recent client engagement, we need to enable SAML proxy for Shibboleth IDP and configure Okta as upstream IDP with all attributes coming into Shibboleth user schema from Okta’s SAML assertion(instead of obtaining this from external directory like
LDAP).<br>
<br>
So far, we achieved the SSO to work as expected and the SSO redirection is happening via Okta IDP. Also referred below documentations and related references for attribute mappings<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP">Using SAML Proxying to another IdP - Shibboleth Knowledge Base - Confluence</a><br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631550/AttributeDefinitionConfiguration">AttributeDefinitionConfiguration - Identity Provider 4 - Confluence</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We tried to use “<b>xsi:type=</b><b><span lang="EN-US">StoredSAML</span></b><span lang="EN-US">” to store the SAML attribute and utilized the same for mapping against the attribute IDs at Shibboleth end. But we could find in one of the
articles that <b>StoredSAML</b> type is deprecated from V4.3.1 onwards.<br>
Also, currently this is setup in a way that the Shibboleth attributes are directly pulled from a LDAP directory post authentication against Proxy AD servers.<o:p></o:p></span></p>
<p class="MsoNormal"><b><span lang="EN-US">Our version: V4.3.3<o:p></o:p></span></b></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">Kindly help us with the alternate configuration to achieve the required attribute mappings which stores and maps the Incoming SAML attributes to Shibboleth user schema.
<br>
Please reach out to me or people in CC for any additional details. </span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks and Regards<br>
Kalidasan S<br>
Advisory - Senior Solution Advisor<br>
<span lang="EN-US" style="mso-ligatures:none">Cyber IAM(Okta) | Deloitte US India Risk and Financial Advisory<o:p></o:p></span></p>
<p class="MsoNormal"><a href="mailto:kalids@deloitte.com"><span lang="EN-US" style="mso-ligatures:none">kalids@deloitte.com</span></a><span lang="EN-US" style="mso-ligatures:none"> |
</span><a href="http://www.deloitte.com/"><span lang="EN-US" style="mso-ligatures:none">www.deloitte.com</span></a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<p>This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law. If you are not the intended recipient, you should delete this message and any disclosure, copying, or distribution
of this message, or the taking of any action based on it, by you is strictly prohibited.</p>
<p>Deloitte refers to a Deloitte member firm, one of its related entities, or Deloitte Touche Tohmatsu Limited ("DTTL"). Each Deloitte member firm is a separate legal entity and a member of DTTL. DTTL does not provide services to clients. Please see www.deloitte.com/about
to learn more.</p>
<p>v.E.1</p>
</body>
</html>