Shib IdP 3 and IOP online service

Maja Wolniewicz mgw at umk.pl
Wed Mar 25 02:57:32 EDT 2015



W dniu 24.03.2015 o 23:53, Tom Zeller pisze:
> On Tue, Mar 24, 2015 at 5:00 PM, Maja Wolniewicz <mgw at umk.pl> wrote:
>> With turned off the per-attribute consent the consent page with
>> eduPersonScopedAffiliation attribute appears but although  I accepted it
>> this attribute isn’t added to the response. Consent record for this SP in
>> the storage doesn’t contain  it as well.
>> eduPersonScopedAffilation has two encoders attached, one of them is
>> net.shibboleth.idp.saml.attribute.encoding.impl.SAML1StringAttributeEncoder.
> To push attributes in the SAML 1 browser SSO profile, you would need
> to set includeAttributeStatement to "true" in relying-party.xml :
>
>   <bean parent="Shibboleth.SSO" p:includeAttributeStatement="true"
> p:postAuthenticationFlows="attribute-release" />
>
> The default is to not push attributes, but users are still prompted
> for consent (because they can't be prompted during back-channel
> attribute query).
>
> Hope this helps.
Yes, thanks for help.

Maja

-- 
Maja Gorecka-Wolniewicz          mgw at umk.pl
Uczelniane Centrum               Information & Communication
Informatyczne                    Technology Centre
Uniwersytet Mikolaja Kopernika   Nicolaus Copernicus University
Coll. Maximum, pl. Rapackiego 1, 87-100 Torun, Poland
tel.: +48 56-611-27-40 fax: +48 56-622-18-50 tel. kom.: +48-693032574


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5278 bytes
Desc: Kryptograficzna sygnatura S/MIME
Url : http://shibboleth.net/pipermail/users/attachments/20150325/8efa0fe4/attachment.bin 


More information about the users mailing list