Shib IdP 3 and IOP online service
Maja Wolniewicz
mgw at umk.pl
Wed Mar 25 02:57:32 EDT 2015
W dniu 24.03.2015 o 23:53, Tom Zeller pisze:
> On Tue, Mar 24, 2015 at 5:00 PM, Maja Wolniewicz <mgw at umk.pl> wrote:
>> With turned off the per-attribute consent the consent page with
>> eduPersonScopedAffiliation attribute appears but although I accepted it
>> this attribute isn’t added to the response. Consent record for this SP in
>> the storage doesn’t contain it as well.
>> eduPersonScopedAffilation has two encoders attached, one of them is
>> net.shibboleth.idp.saml.attribute.encoding.impl.SAML1StringAttributeEncoder.
> To push attributes in the SAML 1 browser SSO profile, you would need
> to set includeAttributeStatement to "true" in relying-party.xml :
>
> <bean parent="Shibboleth.SSO" p:includeAttributeStatement="true"
> p:postAuthenticationFlows="attribute-release" />
>
> The default is to not push attributes, but users are still prompted
> for consent (because they can't be prompted during back-channel
> attribute query).
>
> Hope this helps.
Yes, thanks for help.
Maja
--
Maja Gorecka-Wolniewicz mgw at umk.pl
Uczelniane Centrum Information & Communication
Informatyczne Technology Centre
Uniwersytet Mikolaja Kopernika Nicolaus Copernicus University
Coll. Maximum, pl. Rapackiego 1, 87-100 Torun, Poland
tel.: +48 56-611-27-40 fax: +48 56-622-18-50 tel. kom.: +48-693032574
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5278 bytes
Desc: Kryptograficzna sygnatura S/MIME
Url : http://shibboleth.net/pipermail/users/attachments/20150325/8efa0fe4/attachment.bin
More information about the users
mailing list