no AttributeAuthority role found in metadata

Tom Scavo trscavo at internet2.edu
Thu Sep 19 12:45:10 EDT 2013


On Thu, Sep 19, 2013 at 12:26 PM, Mike Flynn <shibbolethlynda at yahoo.com> wrote:
> Setting up a new connection, everything works fine but I see this in the
> logs:
>
> WARN Shibboleth.AttributeResolver.Query [15]: no SAML 2 AttributeAuthority
> role found in metadata
>
> Do I need to worry about that?

This is becoming a "recommended practice" in the InCommon Federation.
If an IdP *always* pushes attributes, then a SAML2 AttributeService
endpoint is not necessary. Indeed, such an endpoint is known to cause
spurious errors at the SP. (I'm not referring to the warning above.)

Tom


More information about the users mailing list