Logged attribute question
Peter Schober
peter.schober at univie.ac.at
Tue Oct 4 17:22:39 BST 2011
* Mike Flynn <shibbolethlynda at yahoo.com> [2011-10-04 18:10]:
> So, from my side, I get no attributes from them. I have not changed
> any of my configs. My question is this: Does the transaction log
> show all attributes passed regardless of my current attribute
> policy? I seem to recall that it did as I had to do an update to my
> attribute policy for an Idp recently and before I added the
> attributes to my policy, I was able to see them in the tran log.
Attributes filtered out by the SP's attribute policy will only show up
in shibd.log IIRC, same for unmapped atteributes (those not in the
SP's attribute map).
For unmapped NameIDs you'd need to turn up shibd.logger to DEBUG, in
which case you'd see the complete decrypted assertion anyway, so
there'd be no guessing what's included in the assertion or not.
-peter
More information about the users
mailing list