Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Shibboleth - 1.3.2.3. Shibboleth login with persistent-id header and email available #1079

Open
kosarko opened this issue Nov 14, 2023 · 2 comments

Comments

@kosarko
Copy link
Member

kosarko commented Nov 14, 2023

Expectation

Use idp2 and “anon” as the username; the user should be logged in successfully, be in the “Authenticated” and “IDP2” groups (there’s no mapping for the unscoped-affiliation with value “student”), the netid column should be filled in.

Actual

the netid column should be filled in. -> it's not. No mention of config; but when netid-header = eppn,persistent-id...
(other parts not tested, yet)

@milanmajchrak
Copy link
Collaborator

@kosarko
I managed to sign in successfully as the 'anon' user, but the user was only assigned to the 'Authenticated' group and not to 'IDP2'. The netid of the anon user after login looks like this: anon@example.org[https://idptestbed/idp/shibboleth]
Is it OK?

I tested it on our our dev5 testing environment.

@kosarko
Copy link
Member Author

kosarko commented Apr 19, 2024

@milanmajchrak the entityId of idp2 is https://someother/idp/shibboleth (https://github.com/ufal/dockerized-idp-testbed/blob/b3d95d05bcfd8a6080699051df7e85942493cfd3/idp2/shibboleth-idp/conf/idp.properties#L5). So it seems you've logged in through idp1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants