Hello,
with my SAML 2.0 IdP, I'm trying to generate eduPersonTargetedIDs, and
to pass the Interfederation Attribute Test.
https://attribute-viewer.aai.switch.ch/interfederation-test/
I fail for eduPersonTargetedID, and can't figure out why (or rather,
how to configure so that it would work).
I use the following authproc.idp in config.php:
// generate a eduPersonTargetedId, unfortunately in pretty-print format
20 => array(
'class' => 'core:TargetedID',
'attributename' => 'urn:oid:1.3.6.1.4.1.5923.1.1.1.6',
'nameId' => TRUE,
),
// convert eduPersonTargetedId to its URN
25 => array(
'class' => 'core:AttributeMap',
'eduPersonTargetedID' => 'urn:oid:1.3.6.1.4.1.5923.1.1.1.10',
),
I understand that I need the 'nameId' parameter because the persistent
ID should be an attribute, *and* as a name ID in the assertion.
Now, the resulting SAML message does not look like it really does what
it should. Using SAMLTracer, I get this for eduPersonTargetedID:
<saml:Attribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue xsi:type="xs:string"><saml:NameID xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" NameQualifier="
https://clueless.restena.lu/simplesamlphp/saml2/idp/metadata.php" SPNameQualifier="
https://attribute-viewer.aai.switch.ch/interfederation-test/shibboleth" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">c5374b6ad187dfcc839c2043c0af63ce13c82854</saml:NameID></saml:AttributeValue>
</saml:Attribute>
That's an XML blob inside AttributeValue? Is that intentional?
Greetings,
Stefan Winter
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche
6, rue Richard Coudenhove-Kalergi
L-1359 Luxembourg
Tel:
+352 424409 1
Fax:
+352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66