Re: SAML Attribute Processing in 6.6.2 vs 6.5.2
"Derek C. Zoladz" <[email protected]> Mon, 25 Nov 2019 14:52:21 +0000
| Newsgroups | gmane.education.ezproxy |
|---|---|
| Message-ID | <[email protected]> |
Hi, Carrie - I did not hear back from OCLC... but, this makes sense to me after listening to the EZproxy product update from a week ago. Release 6.6.2 includes a new 'SAML attributes can now include spaces' enhancement. A modification to the function that processes the auth: namespace to allow for spaces likely created this unanticipated side effect that broke URN processing during upgrade to 6.5.2. At minimum, the 6.6.2 release notes should highlight the newly required use of quotations around URNs as a step in the upgrade for versions > 6.5.2. Thanks for sharing, -Derek- Derek C. Zoladz, MLIS Library Systems Analyst | Co-Chair, ALAO TEDSIG OhioNET | 1500 W. Lane Avenue | Columbus, Ohio 43221 (614) 484-1074 | [email protected] www.ohionet.org <http://www.ohionet.org> Connecting Libraries for Stronger Communities On 11/25/19, 9:05 AM, "EZproxy List on behalf of Carrie preston" <[email protected] on behalf of [email protected]> wrote: In case you didn't hear back, OCLC eventually suggested putting quotes around the URN's in shibuser.txt (for example, replace auth:urn:oid:1.3.6.1.4.1.5923.1.5.1.1 with auth:"urn:oid:1.3.6.1.4.1.5923.1.5.1.1"). This seemed to solve the issue for one of our two SSO systems that uses URN's formatted like my example. We haven't been able to test yet with our other system that uses schemas.xmlsoap.org URL's. If I add the quote marks to our production system that's still using 6.5.2, it breaks the authentication, so it seems this change needs to be made at the point of upgrade. ******************************************************************** If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences, you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>. Or email [email protected] including the relevant text below in the body of the email: • To unsubscribe: "unsubscribe EZPROXY-L" • To receive EZPROXY-L in digest form: "set EZPROXY-L digest" • To set your options to no mail: "set EZPROXY-L nomail" • To receive these messages in the future "set EZPROXY-L mail" To contact the list owners directly please send your message to [email protected]. If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum. To unsubscribe from all OCLC marketing email communications (including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters), please email us at [email protected]. ******************************************************************** If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences, you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>. Or email [email protected] including the relevant text below in the body of the email: • To unsubscribe: "unsubscribe EZPROXY-L" • To receive EZPROXY-L in digest form: "set EZPROXY-L digest" • To set your options to no mail: "set EZPROXY-L nomail" • To receive these messages in the future "set EZPROXY-L mail" To contact the list owners directly please send your message to [email protected]. If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum. To unsubscribe from all OCLC marketing email communications (including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters), please email us at [email protected].