On 3/6/13 2:02 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote: >Isn't that something you could handle via Shib SP config: supplementing >IdP-delivered attribute assertions with those from another (local in this >case) source? Not via LDAP, unless somebody writes the plugin. Which would be nice. But front-ended with SAML, yes. -- Scott