<div dir="ltr"><div>Hi,</div><div><br></div><div>I now have Shibboleth V5.1.4 partially working with an OpenDJ LDAP instance.  By "partially working", I mean that the Hello World app works and I can authenticate against users in the LDAP server (FYI, the connection to the LDAP server is non-SSL).</div><div><br></div><div>I have also been able to get it connected to another IdP (a COTS IdP), so I have:</div><div><br></div><div>COTS IdP ==> Shibboleth IdP. ==> OpenDJ LDAP server</div><div><br></div><div>Similar to Shibboleth, I think the COTS IdP has a kind of built-in SP, that allows me to test authentication to the Shibboleth IdP (and the LDAP), and it causes an AuthnRequest to be sent to the Shibboleth IdP and then the Shibboleth IdP send a SamlResponse.</div><div><br></div><div>However, the problem I am seeing is that the SAMLResponse does not have a User/Subject/NameID in it, which then causes the COTS IdP to throw an error ("no user found").</div><div><br></div><div>From what I have been able to figure out, I realized that this is because I have not modified the attribute-resolver and the saml-name-id configuration in the Shibboleth IdP yet.</div><div><br></div><div>I've been trying to get those configured, but, unfortunately, my attempts to make those configuration changes led to the point that I crashed the Shibboleth IdP and it wouldn't start.  </div><div><br></div><div>Besides errors with the XML files, I was seeing errors in the idp-warn.log about missing certificate (.crt) files, even though I have TLS set to 'false' in the ldap.properties file.  One other potential problem is that I noticed that in the OpenDJ schema, the email attribute is literally named 'emailAddress', rather than 'mail'.</div><div><br></div><div>Luckily, I had backed up the Shibboleth IdP files that I had changed, so I was able to get the environment back to the point that the Shibboleth IdP is starting/running again, albeit with the SAMLResponse still missing the NameID again.</div><div><br></div><div>At this point, I have some questions that I hope that I can get some help with.</div><div><br></div><div>1) Re. the certificate/.crt errors:  As mentioned, the LDAP server is not SSL-enabled, and in the ldap.properties, I had set the StartTLS parameter to 'false'.  It seems like even if I do that, the IdP is looking for the .crt file.  Do I need to comment out all of the properties that are related to SSL (the truststore ones, etc)?</div><div></div><div>2) Re. the attribute-resolver and the name id, is there maybe minimal versions of those that would work for an LDAP server?</div><div><br></div><div>My apologies, but I HAVE been reading the documentation about attribute-resolver and saml-name-id, and am having a hard time understanding a lot of it.</div><div><br></div><div>Thanks in advance,</div><div>Jim</div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div><div id="DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br><table style="border-top:1px solid #d3d4de"><tr><td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank"><img src="https://s-install.avcdn.net/ipm/preview/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;"></a></td><td style="width:470px;padding-top:12px;color:#41424e;font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free.<a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank" style="color:#4453ea">www.avast.com</a></td></tr></table><a href="#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div>