no AttributeAuthority role found in metadata
Mike Flynn
shibbolethlynda at yahoo.com
Thu Sep 19 16:42:13 EDT 2013
Thanks. Yeah it went away after they started passing attributes.
________________________________
From: "Cantor, Scott" <cantor.2 at osu.edu>
To: Shib Users <users at shibboleth.net>
Sent: Thursday, September 19, 2013 10:05 AM
Subject: Re: no AttributeAuthority role found in metadata
On 9/19/13 12:45 PM, "Tom Scavo" <trscavo at internet2.edu> wrote:
>On Thu, Sep 19, 2013 at 12:26 PM, Mike Flynn <shibbolethlynda at yahoo.com>
>wrote:
>> Setting up a new connection, everything works fine but I see this in the
>> logs:
>>
>> WARN Shibboleth.AttributeResolver.Query [15]: no SAML 2
>>AttributeAuthority
>> role found in metadata
>>
>> Do I need to worry about that?
>
>This is becoming a "recommended practice" in the InCommon Federation.
>If an IdP *always* pushes attributes, then a SAML2 AttributeService
>endpoint is not necessary. Indeed, such an endpoint is known to cause
>spurious errors at the SP. (I'm not referring to the warning above.)
That would be another spurious warning because no attributes were pushed,
but ultimately there's no way to prevent something from being logged
unless the SP just disables queries.
The warning is less noticeable than the errors would be.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130919/2e569975/attachment.html
More information about the users
mailing list