<div dir="ltr"><div dir="ltr"><div>Peter,</div><div><br></div><div>As mentioned earlier, the attribute-resolver.xml is the original one... there is no "MyLDAP" in there. I am on IdP V5.1.4. I just found another file in the conf/examples directory, "conf/examples/attribute-resolver-ldap.xml". <br></div><div><br></div><div>Were you thinking that I had already copied that Are you saying that
"conf/examples/attribute-resolver-ldap.xml" file over the original "conf/attribute-resolver.xml" file?</div><div><br></div><div>Should I copy that
"conf/examples/attribute-resolver-ldap.xml" file to replace the original "conf/attribute-resolver.xml" file (and then removed that line with the "trustFile")?<br></div><div><br></div><div><br></div><div>Also, I have a separate question: As mentioned, I am using an OpenDJ LDAP.... the login for the LDAP is using "cn=Directory Manager", which I have set in one of the properties in the ldap.properties file, but I'd been wondering where the password for the "cn=Directory Manager" is supposed to be set, and I think I just found that is be in the /opt/shibboleth-idp/credentials/secrets.properties.</div><div><br></div><div>That secrets.properties file has:</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"># Default access to LDAP authn and attribute stores.<br>idp.authn.LDAP.bindDNCredential =myServicePassword<br>idp.attribute.resolver.LDAP.bindDNCredential =%{idp.authn.LDAP.bindDNCredential:undefined}</blockquote></div><div dir="ltr"><br></div><div dir="ltr"><br></div><div dir="ltr">I am *assuming* that I should put the password for the "cn=Directory Manager" as the value for the 2nd line (i.e., replace the "myServicePassword" with the password for the "cn=Directory Manager", but I kind of unclear what to do to the 3rd line? Should I also replace the "undefined" with that same password value?</div><div dir="ltr"><br></div><div dir="ltr">Sorry this is all probably kind of confusing :( !!</div><div dir="ltr"><br></div><div dir="ltr">Jim<div><br></div><div><br></div><div><br></div><div><br></div></div><div id="m_-7208505782941769154DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br><table style="border-top:1px solid #d3d4de"><tbody><tr><td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank"><img src="https://s-install.avcdn.net/ipm/preview/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width:46px;height:29px"></a></td><td style="width:470px;padding-top:12px;color:#41424e;font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free.<a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" style="color:#4453ea" target="_blank">www.avast.com</a></td></tr></tbody></table><a href="#m_-7208505782941769154_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Apr 9, 2025 at 2:54 PM Peter Schober via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">o haya via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> [2025-04-09 17:10 CEST]:<br>
> currently I've configured the BEGINNING part of the Shib ldap properties:<br>
[...]<br>
> I have not changed anything in saml-nameid.xml or attribute-resolver.xml (I<br>
> did make changes which caused the IdP to fail to start earlier, but I've<br>
> since restored them to original).<br>
<br>
o haya via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> [2025-04-09 17:31 CEST]:<br>
> Here's what the SAMLResponse I am seeing looks like<br>
[...]<br>
> <saml2:AttributeStatement><br>
> <saml2:Attribute FriendlyName="schacHomeOrganization"<br>
> Name="urn:oid:1.3.6.1.4.1.25178.1.2.9"<br>
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
> <saml2:AttributeValue><a href="http://xxxx.com" rel="noreferrer" target="_blank">xxxx.com</a></saml2:AttributeValue><br>
> </saml2:Attribute><br>
> </saml2:AttributeStatement><br>
> </saml2:Assertion><br>
> </saml2p:Response><br>
<br>
I don't see any questions in those two emails?<br>
<br>
If you're still asking "How do I get the example 'MyLDAP' Data<br>
Connector working with a non-TLS capable LDAP DSA" you've probably<br>
missed my previous reply pointing at the DataConnector's 'trustFile'<br>
parameter which will prevent that, no matter what you're setting in<br>
your ldap.properties.<br>
<br>
HTH,<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>