Why is filter policy not active?

David Bantz dabantz at alaska.edu
Tue Feb 11 15:57:43 EST 2014


DOH!

Thanks Andrew and Michael and yes, for the record, that correctly activates the filter rule to release the right attributes.

David Bantz

On Tue, 11 Feb 2014, at 11:50 , Andrew Morgan <morgan at orst.edu> wrote:

> Isn't the entityID the value of Issuer in the SAML request?  I think you should use "https://demo.origamirisk.com" instead of "https://demo.origamirisk.com/Origami/SSO/SamlLogin?providerAccount=UofAK" in your AttributeRequesterString matching rule.



On Tue, 11 Feb 2014, at 11:51 , Michael A Grady <mgrady at unicon.net> wrote:

> The AttributeRequesterString needs to match the EntityID of the requestor, which is in the Issuer element of that Authn Request. It's just "https://demo.origamirisk.com", without the rest of the URL you have in your current AttributeRequesterString values.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140211/058d56da/attachment.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140211/058d56da/attachment.bin 


More information about the users mailing list