Logged attribute question

Mike Flynn shibbolethlynda at yahoo.com
Tue Oct 4 17:28:22 BST 2011


Do I need to restart ShibD if I change the logging level?



________________________________
From: Peter Schober <peter.schober at univie.ac.at>
To: users at shibboleth.net
Sent: Tuesday, October 4, 2011 9:22 AM
Subject: Re: Logged attribute question

* Mike Flynn <shibbolethlynda at yahoo.com> [2011-10-04 18:10]:
> So, from my side, I get no attributes from them.  I have not changed
> any of my configs.  My question is this:  Does the transaction log
> show all attributes passed regardless of my current attribute
> policy?  I seem to recall that it did as I had to do an update to my
> attribute policy for an Idp recently and before I added the
> attributes to my policy, I was able to see them in the tran log.

Attributes filtered out by the SP's attribute policy will only show up
in shibd.log IIRC, same for unmapped atteributes (those not in the
SP's attribute map).
For unmapped NameIDs you'd need to turn up shibd.logger to DEBUG, in
which case you'd see the complete decrypted assertion anyway, so
there'd be no guessing what's included in the assertion or not.
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20111004/822a6c54/attachment.html 


More information about the users mailing list