<div dir="ltr"><div>Peter,</div><div><br></div><div>Ahhh...</div><div><br></div><div>I set IDP_BASE_URL to <a href="http://localhost:8080/idp">http://localhost:8080/idp</a> and ran the command for users "test1" (exists in LDP) and "test10" (doesn't exist in LDAP) and got:</div><div><br></div><div>/opt/shibboleth-idp/bin/aacli.sh --saml2 -n test1 -r <a href="https://saml.example.org">https://saml.example.org</a><br><?xml version="1.0" encoding="UTF-8"?><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_1bbc6c891c71007cdb5fd632ef1e3163" IssueInstant="2025-04-10T19:43:31.104Z" Version="2.0"><br>    <saml2:Issuer><a href="https://idp01.xxxx.com/idp/shibboleth">https://idp01.xxxx.com/idp/shibboleth</a></saml2:Issuer><br>    <saml2:Subject><br>        <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="<a href="https://idp01.xxxx.com/idp/shibboleth">https://idp01.xxxx.com/idp/shibboleth</a>" SPNameQualifier="<a href="https://saml.example.org">https://saml.example.org</a>">AAdzZWNyZXQxQvJPtSpTNtvrZPNHmm9gI9qdJRNRxK2tdkQ6mSiKxZjr8qf7Dpue+pEfSJ4/XerHfcdUJee5Q/rIWioBvPReiOkNsgeJPCH7VgbuNlM78xgp0yO9ecTmnID577M=</saml2:NameID><br>    </saml2:Subject><br>    <saml2:AttributeStatement><br>        <saml2:Attribute FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>            <saml2:AttributeValue>test1</saml2:AttributeValue><br>        </saml2:Attribute><br>        <saml2:Attribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>            <saml2:AttributeValue><a href="mailto:test1@xxxx.com">test1@xxxx.com</a></saml2:AttributeValue><br>        </saml2:Attribute><br>    </saml2:AttributeStatement><br></saml2:Assertion><br><br><br>/opt/shibboleth-idp/bin/aacli.sh --saml2 -n test10 -r <a href="https://saml.example.org">https://saml.example.org</a><br><?xml version="1.0" encoding="UTF-8"?><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_77770fa5315324f5b79db966d3dea15b" IssueInstant="2025-04-10T19:43:51.848Z" Version="2.0"><br>    <saml2:Subject><br>        <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="<a href="https://idp01.xxxx.com/idp/shibboleth">https://idp01.xxxx.com/idp/shibboleth</a>" SPNameQualifier="<a href="https://saml.example.org">https://saml.example.org</a>">AAdzZWNyZXQxxf5ws6L3aXM77p4q8HSE+SJPQIm1p2nR5MjZMk1Ps8hkflGgVX90xK6F75DsVZemUK23WlB2ZuqCtZ80d1jyyo6lLj/De0aEfvbFcPDB+tvU2m0rL1++s+dihEDs</saml2:NameID><br>    </saml2:Subject><br></saml2:Assertion><br></div><div><br></div><div><br></div><div>Does the above mean that the Shibboleth IdP currently can get the "uid" attribute from the user in LDAP (which we probably do use), and not the "eduPersonPrincipalName" attribute (from the value it looks like that might actually be the emailAddress attribute in the LDAP?) ? <br></div><div><br></div><div>Also does that help for figuring out how to get the NameID to work?</div><div><br></div><div>THANKS!!</div><div><br></div><div>Jim</div></div><div id="DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br><table style="border-top:1px solid #d3d4de"><tr><td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank"><img src="https://s-install.avcdn.net/ipm/preview/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;"></a></td><td style="width:470px;padding-top:12px;color:#41424e;font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free.<a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank" style="color:#4453ea">www.avast.com</a></td></tr></table><a href="#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Apr 10, 2025 at 3:00 PM Peter Schober via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">o haya via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> [2025-04-10 20:03 CEST]:<br>
> Actually, I decided to try what you suggested with the small metadata,<br>
> etc., and, when I tested it, the aacli command line didn't work because of<br>
> the port problem, but I tried to use a curl command with the URL<br>
> [...]<br>
> Connection refused<br>
<br>
<a href="https://shibboleth.net/pipermail/users/2025-April/056331.html" rel="noreferrer" target="_blank">https://shibboleth.net/pipermail/users/2025-April/056331.html</a><br>
w/ correction here:<br>
<a href="https://shibboleth.net/pipermail/users/2025-April/056332.html" rel="noreferrer" target="_blank">https://shibboleth.net/pipermail/users/2025-April/056332.html</a><br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>