Intercept Flows and checking raw LDAP attributes

Jeffrey Crawford jeffreyc at
Mon Aug 3 19:20:36 EDT 2015

I feel like I'm missing something simple here, I have an interrupt flow
that will work based off of the context-check example, however if the SAML
attribute eduPersonAffiliation is not released to the SP in question and
I'm trying to check against it, I get the following in the logs.

Attribute eduPersonAffiliation not found in context

It only works if the attribute-filter has eduPersonAffiliation released to
the SP, but I want to check that attribute even if it's not released, Can I
check against the raw LDAP attribute as opposed to the attributes in the
SAML profile?


Jeffrey <jeffreyc at>

Both pilots and IT professionals require training and currency before
charging into clouds!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the users mailing list