<div dir="ltr"><div> Hi Peter,</div><div><br></div><div>After some discussion, we want the NameID format to be emailAddress, and for the source to be the "cn" attribute. Also "cn" values will be emailAddress format.</div><div><br></div><div>I don't know if it matters but the "cn" attribute is the primary attribute in the LDAP.</div><div><br></div><div>For now, we want the following attributes from the LDAP to be returned in the response (the attribute names below are the attribute names in the LDAP server):</div><div><br></div><ul><li>emailAddress</li><li>givenName</li><li>sn</li></ul><div><br></div><div>From what I have read (and heard from the mailing list), it sounds like I am going to have to modify the following files:</div><div><br></div><div>To enable/configure the attributes:</div><div></div><ul><li>attribute-resolver.xml</li><li>attribute-filter.xml</li></ul><div>To configure the NameID:</div><div></div><div><ul><li>saml-nameid.properties</li></ul></div><div><br></div><div>A couple of questions. </div><div><br></div><div><ul><li>In the saml-nameid.properties, it has this:</li></ul></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">"# Default NameID Formats to use when nothing else is called for.<br># Don't change these just to change the Format used for a single SP!<br>#idp.nameid.saml2.default = F"</blockquote><div><br></div><div>If the "idp.named.saml2.default" shouldn't be used to set NameID format, where should it be set? </div><div><br></div><div>Also, is it correct/ok, to set the NameID format to "urn:oasis:names:tc:SAML:2.0:nameid-format:emailAddress"?</div><div><br></div><div><ul><li>For the attribute-filter.xml, my interpretation was I needed to add something like what you had provided for that non-existent SP earlier, i.e. something like:</li></ul></div><div><br></div><div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><AttributeFilterPolicy id="frontendSP"></blockquote><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <PolicyRequirementRule xsi:type="Requester" value="<a href="https://saml.example.org">https://saml.example.org</a>" /> <<<== Should the "value" be the EntityID of the SP?<br> <AttributeRule attributeID="cn" permitAny="true" /><br> <AttributeRule attributeID="emailAddress" permitAny="true" /><br> <AttributeRule attributeID="givenName" permitAny="true" /><br>
<AttributeRule attributeID="sn" permitAny="true" /><br>
</AttributeFilterPolicy></blockquote><br></div><div><br></div><div>For the attrribute-resolver.xml, I think that I need to add:</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <AttributeDefinition id="cn""><br> <InputDataConnector ref="myLDAP" attributeNames="cn" /><br> </AttributeDefinition></blockquote><blockquote> <AttributeDefinition id="emailAddress"><br> <InputDataConnector ref="myLDAP" attributeNames="emailAddress" /> <<== I am a little unclear about the names. attribute in LDAP is "emailAddress" and was wondering if we could change the name in the response to "mail" instead?<br> </AttributeDefinition></blockquote><blockquote> <AttributeDefinition id="givenName"><br> <InputDataConnector ref="myLDAP" attributeNames="givenName" /><br> </AttributeDefinition></blockquote><blockquote> <AttributeDefinition id="sn"><br> <InputDataConnector ref="myLDAP" attributeNames="sn" /><br> </AttributeDefinition></blockquote><div><br></div><div>I think that I also should to pare down the "exportAttributes"? May be to:</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">exportAttributes="mail sn givenName cn"></blockquote><div><br></div><div><br></div><div>Does that sound about right?</div><div><br></div><div>Thanks for ALL of your help (and patience!).</div><div><br></div><div>Jim</div><div><br></div></div><div id="DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br><table style="border-top:1px solid #d3d4de"><tr><td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank"><img src="https://s-install.avcdn.net/ipm/preview/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;"></a></td><td style="width:470px;padding-top:12px;color:#41424e;font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free.<a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank" style="color:#4453ea">www.avast.com</a></td></tr></table><a href="#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Apr 10, 2025 at 4:59 PM Peter Schober via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">o haya via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> [2025-04-10 22:00 CEST]:<br>
> Does the above mean that the Shibboleth IdP currently can get the<br>
> "uid" attribute from the user in LDAP<br>
<br>
You have your config (attribute-resolver.xml). You can see where it<br>
comes from.<br>
<br>
> Also does that help for figuring out how to get the NameID to work?<br>
<br>
There's no such thing as "a/the NameID": There are different NameID<br>
Formats (and "unspecified" is not a format anyone can sanely require<br>
you to send).<br>
So the first question now is what specific NameID Format the other<br>
system (the other IDP's SP, IIRC) expects to recieve because you can't<br>
just send it "a NameID".<br>
The SAML 2.0 specification includes a few definitions (see section<br>
8.3 in this document,<br>
<a href="https://groups.oasis-open.org/higherlogic/ws/public/download/56777/sstc-saml-core-errata-2.0-wd-07-diff.pdf" rel="noreferrer" target="_blank">https://groups.oasis-open.org/higherlogic/ws/public/download/56777/sstc-saml-core-errata-2.0-wd-07-diff.pdf</a>)<br>
amd you have already seen "transient" NameIDs in your IDP.<br>
(If none of the standard-defined values match your use-case you can<br>
also send other formats. I'll not cover this here.)<br>
<br>
Once you know what NameID Format the SP needs you can decice what<br>
internal attribute in your Shibboleth IDP you want to create this<br>
NameID value from. Which in your case probably means amendng your<br>
attribute resolver conf to look up the required data from LDAP or<br>
elsehwere. Then you can proceed to configure a NameID in the<br>
approriate config files (conf/saml-nameid.*)<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>