release same attributes to a group SPs
Peter Schober
peter.schober at univie.ac.at
Fri Aug 2 03:44:51 EDT 2013
* Nate Klingenstein <ndk at internet2.edu> [2013-08-01 23:12]:
> The "groupID" is actually the name="groupIDGoesHere" element on the
> <EntitiesDescriptor> object. The first paragraph describing the
> example may be helpful.
Name="foo" (not name="foo"), yes.
If you don't control the metadata (or the EntitiesDescriptor around
those SPs contains too much, i.e., entitites you don't want included
in your filter policy) you can release attributes to an enumerated
list of SPs by OR'ing them together, like in the second example in
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPFilterRequirementAttributeRequesterString
-peter
More information about the users
mailing list