no AttributeAuthority role found in metadata
Cantor, Scott
cantor.2 at osu.edu
Thu Sep 19 13:05:19 EDT 2013
On 9/19/13 12:45 PM, "Tom Scavo" <trscavo at internet2.edu> wrote:
>On Thu, Sep 19, 2013 at 12:26 PM, Mike Flynn <shibbolethlynda at yahoo.com>
>wrote:
>> Setting up a new connection, everything works fine but I see this in the
>> logs:
>>
>> WARN Shibboleth.AttributeResolver.Query [15]: no SAML 2
>>AttributeAuthority
>> role found in metadata
>>
>> Do I need to worry about that?
>
>This is becoming a "recommended practice" in the InCommon Federation.
>If an IdP *always* pushes attributes, then a SAML2 AttributeService
>endpoint is not necessary. Indeed, such an endpoint is known to cause
>spurious errors at the SP. (I'm not referring to the warning above.)
That would be another spurious warning because no attributes were pushed,
but ultimately there's no way to prevent something from being logged
unless the SP just disables queries.
The warning is less noticeable than the errors would be.
-- Scott
More information about the users
mailing list