> I am seeing the following lines in my idp-process.log: On DEBUG, I would imagine, since that's just a trace message during the NameID encoding process. > The attributes are then of course not released to the SP. That isn't relevant to SAML attribute release, only encoding of the subject of the assertion. -- Scott