Default RP config for SAML 1 and attribute-release ?
Tom Zeller
tzeller at dragonacea.biz
Sun Dec 21 18:00:45 EST 2014
> On Dec 21, 2014, at 4:47 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>> On 12/21/14, 10:42 PM, "Tom Zeller" <tzeller at dragonacea.biz> wrote:
>>
>> Well then, per-attribute should not be enabled for SAML 1. Correct ?
>> Because if ReleaseAttributes is not wired, the user's choices are not
>> honored.
>
> Correct.
>
> I left the default for per-attribute set to false, because I thought we
> wanted to go ahead and stick to basic uApprove behavior by default.
Okay.
> The predicate I wired in for the flow will automatically turn it off for
> SAML 1 though, if you change the per-attribute setting.
Ah, that I did not know.
> The only place it breaks down is if support for queries with a different
> kind of ID is enabled, but that's generally rare.
Thanks.
More information about the dev
mailing list