<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof">Hi,</div>
<div class="elementToProof"><br>
</div>
<div class="elementToProof">OK thank you gave some good clues were to look</div>
<div class="elementToProof"><br>
</div>
<div class="elementToProof">And I found the reason. The bind user I'm using from the IDP doesn't seem to have enough rights to get
<span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
funetEduPersonLearnerId</span></div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I'd been using a different user always with ldapsearch than what I have in ldap.properties</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
ldapsearch with the IDP bind user doesn't get the funetEduPersonLearnerId</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
but the other user does.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
If it starts to work I'll keep the long namespaces for now but good hint.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Yep and a quick test with</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
bin/aacli.sh --configDir=conf/ --principal=testte08 -r <a href="https://idp.staging.opin.fi/" id="LPlnk144369">
https://idp.staging.opin.fi</a></div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
and I get the correct attributes 🙂</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-size:12pt;font-family:Calibri, Arial, Helvetica, sans-serif;color:rgb(0, 0, 0);background-color:rgb(255, 255, 255)">
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
Terveisin/Regards</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
<b> </b></div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
<b>Scott Alexander</b></div>
<div style="margin: 0px;"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: black;">Asiantuntija, järjestelmät
</span><span style="font-family: Calibri, sans-serif; font-size: 9pt; color: black;"></span><span style="font-family: "Calibri", sans-serif; font-size: 11pt; color: rgb(31, 73, 125);">Systems Specialist</span></div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 11pt; color: black;">
Humak</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
Humanistinen ammattikorkeakoulu</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
University of Applied Sciences</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
<a href="http://www.humak.fi/" target="_blank" id="OWAbba3fe4d-f098-ebe2-f967-64615414453b" class="OWAAutoLink">www.humak.fi</a></div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
Tel. +358 (0)50 411 9556<br>
<br>
</div>
<div style="margin: 0px; font-family: Calibri, sans-serif; font-size: 9pt; color: black;">
<a href="mailto:scott.alexander@humak.fi" target="_blank" id="OWAd918917d-dda2-d228-7359-f84b5e83aebc" class="OWAAutoLink">scott.alexander@humak.fi</a></div>
</div>
</div>
<div id="appendonsend"></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div dir="ltr" id="divRplyFwdMsg"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober via users <users@shibboleth.net><br>
<b>Sent:</b> 30 January 2025 19:22<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Peter Schober <peter.schober@univie.ac.at><br>
<b>Subject:</b> Re: Trying to release new attribute funetEduPersonLearnerId</span>
<div> </div>
</div>
<div class="elementToProof" style="font-size: 11pt;">Scott Alexander via users <users@shibboleth.net> [2025-01-30 12:52 CET]:<br>
> 2025-01-30 13:22:50,088 - DEBUG<br>
> [net.shibboleth.idp.attribute.resolver.AbstractAttributeDefinition:137] - Attribute Definition 'id-urn:mace:funet.fi:attribute-def:funetEduPersonLearnerId': produced an attribute with no values<br>
<br>
Probably not related to your current issue but note that I find<br>
"id-urn:mace:funet.fi:attribute-def:funetEduPersonLearnerId" to be a<br>
highly unusual and needlessly complex internal attribute id for an<br>
AttributeDefinition within the IDP's resolver:<br>
There's no reason to qualify internal ids with global namespaces --<br>
that's what happens during the encoding phrase, releasing data with<br>
the appropriate names and namespaces for the chosen protocol.<br>
Just call it "funetEduPersonLearnerId" within your attribute resolver,<br>
filter and possibly registry.<br>
<br>
(And one of the benefits of using the Attribute Registry is that you<br>
no longer have to have any of those fully qualified on-the-wire<br>
attribute names within your resolver configuration. If you chose to<br>
use the Attribute Registry, which you don't have to: Your<br>
AttributeEncoder elements with your resolver are fine, you don't have<br>
to put/move that into the Attribute Registry. In fact if you do it on<br>
both places you'll experience the infamous "duplicate attribute<br>
values" issue due to, well, duplicate encoding.)<br>
<br>
Also note that if your attribute is called funetEduPersonLearnerId in<br>
LDAP a simple entry in the Attribute Registry (for the encoding) would<br>
suffice, you wouldn't even have to have an AttributeDefinition for it<br>
in your resolver! You'd simply add it to your LDAP<br>
DataConnector/@exportAttributes.<br>
<br>
> Data connector 'AD1' resolved the following attributes:<br>
<br>
There's no sign of an funetEduPersonLearnerId attribute there.<br>
<br>
That seems to point to a difference in how the LDAP client within the<br>
IDP talks to your LDAP directory vs. your (not fully representative,<br>
is what I'm saying) test with ldapsearch.<br>
<br>
What idp.authn.LDAP.authenticator is your IDP configured to use?<br>
If that's adAuthenticator then the ldapsearch command cannot possibly<br>
replicate that (as ldapsearch only supports LDAPv3, not the proprietary<br>
extensions from M$), for example.<br>
<br>
HTH,<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" id="OWA559bd2f9-bba0-b335-1325-7aa9eef6fb54" class="OWAAutoLink" data-auth="NotApplicable">
https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7C%7Cf9d227bb0de44c97abf208dd4152be08%7Ca30a558eb6084b2c8f39a7fa426fa49d%7C0%7C0%7C638738545814531158%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=c%2FQoU95xf9kLdp3EEfSjI62YOvlF94tZksuodYguhYk%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div>
</body>
</html>