Where is your attributeRepository used in the configuration?


From: [email protected] [mailto:[email protected]] On Behalf Of David 
Abney
Sent: Tuesday, January 26, 2016 6:36 AM
To: [email protected]
Subject: [cas-user] Alternate Username with SAML 2.0



I have CAS 4.0.7 running and I’m testing using a different value from LDAP 
to authenticate with a service that uses the SAML 2.0 (Google Apps) support 
provided by CAS.  I would like to use the employeeID attribute from Active 
Directory as the principal Id for this service only.  I have tried this 
setup:



Setup in deployerConifgContext.xml file:

<bean id="attributeRepository" 
class="org.jasig.services.persondir.support.StubPersonAttributeDao"

            p:backingMap-ref="attrRepoBackingMap" />



    <util:map id="attrRepoBackingMap">

        <entry key="uid" value="uid" />

        <entry key="mail" value="mail" />

        <entry key="employeeID" value="employeeID" />

</util:map>



<bean class="org.jasig.cas.services.RegexRegisteredService">

            <property name="id" value="5" />

            <property name="name" value="---service name---" />

            <property name="description" value="---service description---" 
/>

                <property name="serviceId" value="---server url---" />

            <property name="evaluationOrder" value="5" />

            <property name="usernameAttribute" value="employeeID" />

            <property name="allowedAttributes">

                <list>

                    <value>employeeID</value>

                </list>

            </property>

        </bean>



<bean id="ldapAuthenticationHandler"

      class="org.jasig.cas.authentication.LdapAuthenticationHandler"

      p:principalIdAttribute="sAMAccountName"

      c:authenticator-ref="authenticator">

    <property name="principalAttributeMap">

        <map>

            <!--

               | This map provides a simple attribute resolution mechanism.

               | Keys are LDAP attribute names, values are CAS attribute 
names.

               | Use this facility instead of a PrincipalResolver if LDAP is

               | the only attribute source.

               -->

            <entry key="displayName" value="displayName" />

            <entry key="mail" value="mail" />

            <entry key="employeeID" value="employeeID" />

        </map>

    </property>

</bean>



Setup in the argumentExtractorsConfiguration.xml file:

<bean id="googleAccountsArgumentExtractor"

                
class="org.jasig.cas.support.saml.web.support.GoogleAccountsArgumentExtractor"

                p:privateKey-ref="privateKeyFactoryBean"

                p:publicKey-ref="publicKeyFactoryBean"

                p:alternateUsername="employeeID" />



However, in the SAML assertion that comes from CAS, the name id that is sent 
over is just the text “employeeID” instead of the actual employee ID 
attribute in Active Directory.  Any thoughts on why it isn’t sending the 
employee ID value?  If I remove the alternateUsername field from the 
googleAccountsArgumentExtractor, then CAS does send over the sAMAccountName 
like it normally should.



Thanks,



David Abney

-- 
You received this message because you are subscribed to the Google Groups 
"CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an 
email to [email protected] 
<mailto:[email protected]> .
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to