Hi, Mac,

I got the JSON service definition below working with TestShib. Instead of
having the attribute repository map the LDAP attribute names, I let the
attribute release policy do that instead. The last two attributes show how
to populate a SAML attribute using Groovy, in this case the mail and uid
attributes. I also override the username attribute here, populating it with
the value of the mail attribute.

{
  @class: org.apereo.cas.support.saml.services.SamlRegisteredService
  serviceId: https://sp.testshib.org/shibboleth-sp
  name: testshibsp
  id: 2
  description: TestShib Test SP
  metadataLocation: http://www.testshib.org/metadata/testshib-providers.xml
  signAssertions: false
  signResponses: true
  encryptAssertions: false
  evaluationOrder: 0
  usernameAttributeProvider:
  {
    @class:
org.apereo.cas.services.PrincipalAttributeRegisteredServiceUsernameProvider
    usernameAttribute: "urn:oid:0.9.2342.19200300.100.1.3"
    canonicalizationMode: NONE
    encryptedUsername: false
  }
  attributeNameFormats:
  {
    @class: java.util.HashMap
    "urn:oid:2.16.840.1.113730.3.1.241": uri
    "urn:oid:2.5.4.42": uri
    "urn:oid:2.5.4.4": uri
    "urn:oid:0.9.2342.19200300.100.1.60": uri
    "urn:oid:2.16.840.1.113730.3.1.39": uri
    "urn:oid:0.9.2342.19200300.100.1.3": uri
    "urn:oid:0.9.2342.19200300.100.1.1": uri
  }
  attributeReleasePolicy:
  {
    @class: org.apereo.cas.services.ReturnMappedAttributeReleasePolicy
    allowedAttributes:
    {
        @class: java.util.TreeMap
        displayName: "urn:oid:2.16.840.1.113730.3.1.241"
        name.givenName: "urn:oid:2.5.4.42"
        name.familyName: "urn:oid:2.5.4.4"
        image.url: "urn:oid:0.9.2342.19200300.100.1.60"
        language: "urn:oid:2.16.840.1.113730.3.1.39"
        "urn:oid:0.9.2342.19200300.100.1.3": "groovy { return
attributes['emails'][0].getEmail() }"
        "urn:oid:0.9.2342.19200300.100.1.1": "groovy { return
attributes['emails'][0].getEmail().replaceFirst(/@.*$/,'') }"
    }
    principalAttributesRepository:
    {
      @class:
org.apereo.cas.authentication.principal.DefaultPrincipalAttributesRepository
      expiration: 2
      timeUnit: HOURS
    }
    authorizedToReleaseCredentialPassword: false
    authorizedToReleaseProxyGrantingTicket: false
    excludeDefaultAttributes: false
  }
  multifactorPolicy:
  {
    @class:
org.apereo.cas.services.DefaultRegisteredServiceMultifactorPolicy
    failureMode: CLOSED
    bypassEnabled: false
  }
  accessStrategy:
  {
    @class: org.apereo.cas.services.DefaultRegisteredServiceAccessStrategy
    enabled: true
    ssoEnabled: true
    requireAllAttributes: true
    caseInsensitive: false
  }
}



Carlos

Carlos Fernandez | Solutions Architect

[email protected]

215.297.440 <215-297-4400>0

751 Arbor Way, Hillcrest I, Suite 150
Blue Bell, PA 19422

www.coredial.com <https://coredial.com/>
<https://twitter.com/coredial>
<https://www.linkedin.com/company/coredial-llc>
<https://plus.google.com/+Coredial> <https://success.coredial.com/blog>

The information transmitted is intended only for the person or entity to
which it is addressed and may contain confidential and/or privileged
material. Any review, retransmission, dissemination or other use of, or
taking of any action in reliance upon, this information by persons or
entities other than the intended recipient is prohibited. If you received
this in error, please contact the sender and delete the material from any
computer.

On Fri, Nov 10, 2017 at 11:17 AM, Mac Reid <[email protected]> wrote:

> Hi all,
>
> When releasing attributes to a SAML service, is there a way to change the
> Name field (in the resulting SAML response) to use the SAML 1 or 2
> definitions rather than the attribute name? That is, can the Name field be
> set to urn:oid:2.5.4.4 (<saml2:Attribute Name="urn:oid:2.5.4.4">) instead
> of sn (<saml2:Attribute Name="sn">)? The default Shibboleth Service
> Provider 2 attribute-map uses the urn:oid format, not the attribute name.
>
> I've tried changing the attribute repository to map sn to the oid
> (cas.authn.attributeRepository.ldap[0].attributes.sn=urn:oid:2.5.4.4),
> but then the attribute doesn't get pulled in from ldap. The
> setting cas.authn.samlIdp.response.useAttributeFriendlyName=false just
> removes the FriendlyName field.
>
> Thanks,
>
> Mac Reid
>
> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/10d6ca0d-342a-4a5f-9351-
> 086bea3c18d0%40apereo.org
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/10d6ca0d-342a-4a5f-9351-086bea3c18d0%40apereo.org?utm_medium=email&utm_source=footer>
> .
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CANUog5Y4PC070Q_pK4jJTqXqz_E%3D1i2Rq1TRDLXV25KPBoLG1w%40mail.gmail.com.

Reply via email to