Default RP config for SAML 1 and attribute-release ?

Tom Zeller tzeller at dragonacea.biz
Sun Dec 21 18:00:45 EST 2014



> On Dec 21, 2014, at 4:47 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> 
>> On 12/21/14, 10:42 PM, "Tom Zeller" <tzeller at dragonacea.biz> wrote:
>> 
>> Well then, per-attribute should not be enabled for SAML 1. Correct ? 
>> Because if ReleaseAttributes is not wired, the user's choices are not 
>> honored.
> 
> Correct.
> 
> I left the default for per-attribute set to false, because I thought we 
> wanted to go ahead and stick to basic uApprove behavior by default.

Okay.

> The predicate I wired in for the flow will automatically turn it off for 
> SAML 1 though, if you change the per-attribute setting.

Ah, that I did not know.

> The only place it breaks down is if support for queries with a different 
> kind of ID is enabled, but that's generally rare.

Thanks.


More information about the dev mailing list