Attribute Filters using DefaultRelyingParty

Cantor, Scott cantor.2 at osu.edu
Mon Mar 31 12:55:42 EDT 2014


On 3/31/14, 12:30 PM, "Jeffrey Crawford" <jeffreyc at ucsc.edu> wrote:
>
>However we noticed that for entity id's were we didn't have a relying
>party entry, but were allowed to login because they were caught in the
>DefaultRelyingParty, the filters we defined stopped
> working if we used the AttributeRequesterString in the
>AttributeFilterPolicy.

That's not the case, so you're misinterpreting something.

>Is there a reason why AttributeFilterPolicys AttributeRequesterString
>would ignore the entity ID and not apply filters if using
>DefaultRelyingParty as opposed to RelyingParty.

They have literally nothing to do with each other, there's no relationship
between the two designations.

Whatever you observed is not a bug I have any recollection of, but I
couldn't say for sure other than that all versions of the IdP going back
to certainly 2.2 or so when I first ran it definitely support this fine. I
use it every day that way.

-- Scott




More information about the users mailing list