ERROR in LOGS IdPv3

John Morrison john.morrison at uadm.uu.se
Thu Aug 25 12:07:12 EDT 2016


On Thu, 2016-08-25 at 16:00 +0000, John Morrison wrote:
> On Thu, 2016-08-25 at 11:50 +0000, John Morrison wrote:
> > On Wed, 2016-08-24 at 18:01 +0000, Cantor, Scott wrote:
> > > On 8/24/16, 11:59 AM, "users on behalf of John Morrison" <users-bounces at shibboleth.net on behalf of john.morrison at uadm.uu.se> wrote:
> > > 
> > > >    I am using the new method of nameid generation and not using the
> > > >    resolver data connector as previously in version2.
> > > 
> > > Ok, but:
> > > 
> > > >    attribute-resolver.xml:
> > > 
> > > All of that is the old stuff, being used to embed the NameID in an AttributeValue. There's no "new" way to do that, in fact, we just deprecated the idea itself a long time back, and there is no "newer" way to generate it in V3. It's not going away, but regardless, that is NOT the new "nameid generation" stuff.
> > > 
> > > And it *will* run for CAS. So...that's why it's happening.
> > > 
> > > -- Scott
> > > 
> > > 
> > 
> > Is there anyway I can block for all CAS auths to not release
> > eduPersonTargetedID.
> > 
> > You can't do a wild card filter, I've notice in the filter, to deny an
> > attribute.
> > 
> > 
> > Cheers,
> > 
> > 
> > //John
> > 
> 
> 
> Yes, I found out you can make a CAS group in cas-protocol.xml and then
> use    <PolicyRequirementRule xsi:type="InEntityGroup"
>         groupID="CAS"/>
> 
> to deny that attribute. (EPTID) in the attribure-filter.xml
> 
> 
> Thanks,
> 
> 
> 
> John


But still generates into the database. :(   

There is no way to stop persistentID being generated just for CAS in
anyway I suppose!


John


More information about the users mailing list