I've been trying unsuccessfully to get Shibboleth groups and federated login working for UCLA Dataverse. The idea was any other campus can log in via Federated but only UCLA affiliated users could create dataverses or datasets. The Shibboleth group would identify the UCLA users and assign appropriate permissions.
@Don Sizemore and Jim Myers checked the json file I used to try and create the Shibboleth group and based on what they saw it should work.
Is it possible to compare my configuration files with anyone else's?
Sure, can you please share your JSON file here?
These are the last 2 that I tried:
{
"name" : "UCLA Affiliated Users idp",
"attribute" : "Shib-Identity Provider",
"pattern" : "ucla.edu"
}
{
"name" : "UCLA Affiliated Users idp",
"attribute" : "Shib-Identity Provider",
"pattern" : "https://shib.ais.ucla.edu/shibboleth-idp/"
}
I would suggest trying urn:mace:incommon:ucla.edu as the pattern based on what I'm seeing at https://incommon.org/custom/federation/info/all-idps-certified.html for UCLA.
Philip Durbin said:
I would suggest trying
urn:mace:incommon:ucla.eduas the pattern based on what I'm seeing at https://incommon.org/custom/federation/info/all-idps-certified.html for UCLA.
I think it works! We had rolled back the login to UCLA-only. I guess we'll try again and report back.
Fantastic!
I moved your problem 2 to #troubleshooting > DiscoFeed timeout
I'm glad the original problem is solved!
Thank you. I'm going to be gone tues-friday for the ICPSR biannual meeting.
Last updated: Jan 09 2026 at 14:18 UTC