<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Vijaya;}
@font-face
{font-family:-apple-system;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;
mso-ligatures:none;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN">Hi Team,<br>
<br>
We are working on a client engagement, where we have enabled SAML proxy for Shibboleth IDP and configure Okta as upstream IDP for SSO. We are following hybrid approach for fetching attributes from Okta’s LDAP interface. Previously the data used to be pulled
from Open DJ LDAP which is now replaced with Okta LDAP.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN">We have observed that due to differences in directories structure and Data Type between Open DJ & Okta LDAP because of which the multivalued attributes sent from
Okta LDAP mapped to Shibboleth objects are getting manipulated, with open/close brackets [] & comma separated considering as single attribute in Shibboleth generated SAML assertion as shown in below logs<o:p></o:p></span></p>
<p class="MsoNormal"><b><u><span lang="EN-IN">Shibboleth Generated SAML Assertion for Attribute from Open DJ LDAP:<o:p></o:p></span></u></b></p>
<p class="MsoNormal"><b><u><span lang="EN-IN"><o:p><span style="text-decoration:none"> </span></o:p></span></u></b></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN"><saml2:Attribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN"><saml2:AttributeValue xmlns:xsd=<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a> xmlns:xsi=<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>
xsi:type="xsd:string"><a href="mailto:member@ucsf.edu%3c/saml2:AttributeValue"><span style="background:yellow;mso-highlight:yellow">member@ucsf.edu</span><span style="color:windowtext;text-decoration:none"></saml2:AttributeValue></span></a><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN"> <saml2:AttributeValue xmlns:xsd=<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a> xmlns:xsi=<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>
xsi:type="xsd:string"><a href="mailto:affiliate@ucsf.edu%3c/saml2:AttributeValue"><span style="background:yellow;mso-highlight:yellow">affiliate@ucsf.edu</span><span style="color:windowtext;text-decoration:none"></saml2:AttributeValue></span></a><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN"> </saml2:Attribute><o:p></o:p></span></p>
<p class="MsoNormal"><b><u><span lang="EN-IN">Shibboleth Generated SAML Assertion for Attribute from Okta LDAP:<o:p></o:p></span></u></b></p>
<p class="MsoNormal"><b><u><span lang="EN-IN"><o:p><span style="text-decoration:none"> </span></o:p></span></u></b></p>
<p class="MsoNormal"><span lang="EN-IN"><saml2:Attribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-IN"> <saml2:AttributeValue xmlns:xsd=<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a> xmlns:xsi=<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>
xsi:type="xsd:string"><span style="background:yellow;mso-highlight:yellow">[affiliate, member]@ucsf.edu</span></saml2:AttributeValue><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-IN"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><u><span lang="EN-IN">Attribute Value stored in Okta LDAP:<o:p></o:p></span></u></b></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN"><img border="0" width="424" height="65" style="width:4.4166in;height:.6805in" id="Picture_x0020_1" src="cid:image001.png@01DB3789.D15D6E10"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span lang="EN-IN">Okta LDAP is storing this attribute value in String-Array datatype but when this attributes are getting resolved at
<b>eduPersonScopedAffiliation </b>attribute in Shibboleth, it manipulates the data as a comma separated single value & array values enclosed in [] brackets.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><b><span lang="EN-IN">eduPersonScopedAffiliation</span></b><span lang="EN-IN"> is scoped attribute in Shibboleth which is
</span><span style="font-size:12.0pt;font-family:-apple-system;color:#172B4D;letter-spacing:-.05pt;background:white">a domain-valued suffix, to an input attribute's values.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:12.0pt;font-family:-apple-system;color:#172B4D;letter-spacing:-.05pt;background:white">We have attribute resolver in our Shibboleth configuration which resolves
the above scoped attribute and please find below snippet section that handles the transformation for reference<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="background:yellow;mso-highlight:yellow"><AttributeDefinition id="eduPersonScopedAffiliation"<br>
xsi:type="Scoped"<br>
scope="ucsf.edu"<br>
></span><br>
<span style="background:yellow;mso-highlight:yellow"><InputDataConnector ref="oktaLDAP" attributeNames="edupersonaffiliation" /><br>
<DisplayName>Education Person Scoped Affiliation</DisplayName><br>
<DisplayDescription>Your affiliation with UCSF in a special format used by some applications.</DisplayDescription><br>
<AttributeEncoder xsi:type="SAML1ScopedString"<br>
name="urn:mace:dir:attribute-def:eduPersonScopedAffiliation" /><br>
<AttributeEncoder xsi:type="SAML2ScopedString"<br>
name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" friendlyName="eduPersonScopedAffiliation" /><br>
</AttributeDefinition></span><span lang="EN-IN"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><b>Our Shibboleth IDP version: V4.3.3</b><span lang="EN-IN"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Kindly help us with the required configuration or changes needs to put in place, by which we can stores and maps the Incoming SAML multivalued attributes to Shibboleth attributes
resolver as is without being altered as single value comma separated and enclosed in brackets. Also can you please help us with any reference that talks about Shibboleth user schema & its datatypes<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><br>
Please reach out to me or people in CC for any additional details. <span lang="EN-IN">
<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-IN" style="font-size:12.0pt;font-family:"Vijaya",serif;mso-ligatures:standardcontextual">Best Regards,<br>
Vinay Bhruguwar<br>
Advisory - Senior Solution Advisor<br>
</span><span style="font-size:12.0pt;font-family:"Vijaya",serif">Cyber IAM | Deloitte US India Risk and Financial Advisory<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Vijaya",serif"><a href="mailto:vbhruguwar@deloitte.com"><span style="color:#0563C1">vbhruguwar@deloitte.com</span></a> |
</span><span lang="EN-IN" style="font-size:12.0pt;font-family:"Vijaya",serif;mso-ligatures:standardcontextual"><a href="http://www.deloitte.com/"><span lang="EN-US" style="color:#0563C1;mso-ligatures:none">www.deloitte.com</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Vijaya",serif;color:#75787B;mso-ligatures:standardcontextual">Please consider the environment before printing.</span><span style="font-size:12.0pt;font-family:"Vijaya",serif;color:#92D400;mso-ligatures:standardcontextual"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-ligatures:standardcontextual"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-ligatures:standardcontextual"><o:p> </o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<p>This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law. If you are not the intended recipient, you should delete this message and any disclosure, copying, or distribution
of this message, or the taking of any action based on it, by you is strictly prohibited.</p>
<p>Deloitte refers to a Deloitte member firm, one of its related entities, or Deloitte Touche Tohmatsu Limited ("DTTL"). Each Deloitte member firm is a separate legal entity and a member of DTTL. DTTL does not provide services to clients. Please see www.deloitte.com/about
to learn more.</p>
<p>v.E.1</p>
</body>
</html>