Hi,
>
> with help of Roland Hedberg's freeradius_pysaml2 module (not using ECP)
> for freeradius server we managed to use a Shibboleth IdP to deliver
> attributes for authorization. But the received SAML assertion is not
> forwarded from freeradius server back to requesting service (e.g. SSHD).
copy_request_to_tunnel
you will also need to check your attr filtering to ensure that the attributes
are not being stripped out when proxying. radiusd -X output will show whats going on.
alan
|