<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Oct 23, 2017, at 6:37 PM, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" class="">cantor.2@osu.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class=""><blockquote type="cite" style="font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" class="">Another thing I've wondered, but so far have shied away from, is an embedded filter config that would be a "Not/deny". But<br class="">there is no distributed example of a resolver ID for a "suppress" attribute. So that would have to be a property or just<br class="">make up a value and say "if you want to leverage the standard config, use that ID, even if it means just sourcing it from the ID<br class="">you are already creating".<br class=""></blockquote><br style="font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""><span style="font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">You mean the FERPA type thing? I figured we'd just define something, yes. I guess some of that could be turned into properties, but I just think that's more confusing than helpful.</span></div></div></blockquote><br class=""></div><div>Yes. I have to say, I work with a lot of institutions, and almost none have even had any attribute in their directory to indicate "elected FERPA suppression" or some related suppress-type indicator. So I've rarely seen it's use in attribute filter files. But it would be easy to say, "if you want to suppress sending attributes for a person", create an attribute id "suppress" with a value of true (or "yes"). And then have an entity attribute activated config in the filter that looks for that id/value, and an entity attribute of "honor suppression", and have that deny all the attributes that one creates entity attribute-based release rules for. (Again, one could get more detailed and have a "suppress entity attribute value per-attribute, so a suppress-givenName value, in conjunction with a givenName value, would release givenName to that SP unless the person in question had the attribute "suppress=true". But that again is driving the complexity up (and probably the understanding "down".)</div><br class=""><div class="">
<div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.</div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" class=""><br class=""></div><br class="Apple-interchange-newline">

</div>
<br class=""></body></html>