Shibboleth 5 IDP添加SAML断言静态属性未显示问题求助
问题排查与解决方案
从你的日志和配置来看,LastName属性已经通过过滤且IDP内部已识别(Audit日志里也列出了该属性),但未出现在SAML断言中,核心问题是缺少SAML属性编码器配置,以及可能的SP依赖方属性发布策略限制。
1. 必须添加SAML AttributeEncoder到自定义属性定义
Shibboleth 5需要显式配置属性编码器,才能将内部属性映射为SAML断言中的属性。你的示例属性(如uid、mail)肯定包含了编码器配置,而LastName没有。
修改你的LastName属性定义,添加编码器:
<AttributeDefinition id="LastName" xsi:type="Simple"> <InputDataConnector ref="staticAttributes" attributeNames="dcLastName" /> <!-- 添加SAML 2.0属性编码器,指定断言中的属性标识 --> <AttributeEncoder xsi:type="SAML2AttributeEncoder" name="urn:oid:2.5.4.4" <!-- 可选,使用标准LastName OID,也可以自定义URI --> friendlyName="LastName" attributeNamespace="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" /> </AttributeDefinition>
name:断言中属性的唯一标识符(可以用OID或自定义URI)friendlyName:SP端可见的友好名称attributeNamespace:指定属性名称格式,通常用URI格式
2. 确认SP依赖方的属性发布策略
确保目标SP(urn:consumer_sp1)的依赖方配置允许发布LastName属性:
在relying-party.xml中检查对应SP的配置,添加属性规则:
<rp:RelyingParty id="urn:consumer_sp1" provider="https://your-idp.example.org/idp/shibboleth"> <rp:ProfileConfiguration xsi:type="saml:SAML2SSOProfile"> <!-- 保留原有SSO配置 --> </rp:ProfileConfiguration> <!-- 配置属性过滤策略,允许LastName发布给该SP --> <rp:AttributeFilterPolicy> <rp:PolicyRequirementRule xsi:type="basic:ANY" /> <rp:AttributeRule attributeID="LastName"> <rp:PermitValueRule xsi:type="basic:ANY" /> </rp:AttributeRule> <!-- 其他需要发布的属性规则 --> </rp:AttributeFilterPolicy> </rp:RelyingParty>
如果使用默认的全局属性过滤策略,确保全局规则允许LastName通过。
3. 验证配置并重启IDP
- 执行配置验证命令,检查语法错误:
./bin/idp.sh validate-config - 重启Shibboleth IDP服务,重新发起SSO请求,检查断言是否包含
LastName。
内容的提问来源于stack exchange,提问作者Philipp Grigoryev
相关产品推荐
相关产品推荐

