no AttributeAuthority role found in metadata

Mike Flynn shibbolethlynda at yahoo.com
Thu Sep 19 16:42:13 EDT 2013


Thanks.  Yeah it went away after they started passing attributes.


________________________________
 From: "Cantor, Scott" <cantor.2 at osu.edu>
To: Shib Users <users at shibboleth.net> 
Sent: Thursday, September 19, 2013 10:05 AM
Subject: Re: no AttributeAuthority role found in metadata
 

On 9/19/13 12:45 PM, "Tom Scavo" <trscavo at internet2.edu> wrote:

>On Thu, Sep 19, 2013 at 12:26 PM, Mike Flynn <shibbolethlynda at yahoo.com>
>wrote:
>> Setting up a new connection, everything works fine but I see this in the
>> logs:
>>
>> WARN Shibboleth.AttributeResolver.Query [15]: no SAML 2
>>AttributeAuthority
>> role found in metadata
>>
>> Do I need to worry about that?
>
>This is becoming a "recommended practice" in the InCommon Federation.
>If an IdP *always* pushes attributes, then a SAML2 AttributeService
>endpoint is not necessary. Indeed, such an endpoint is known to cause
>spurious errors at the SP. (I'm not referring to the warning above.)

That would be another spurious warning because no attributes were pushed,
but ultimately there's no way to prevent something from being logged
unless the SP just disables queries.

The warning is less noticeable than the errors would be.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130919/2e569975/attachment.html 


More information about the users mailing list