SimpleAttributePredicate case insensitive
Cantor, Scott
cantor.2 at osu.edu
Thu Feb 16 13:09:59 EST 2017
> On a related note - why doesn't the IDP log when access is denied (the
> context check fails)? All I see is an audit entry with no nameID or
> attributes listed.
I'd have to look at it, my recollection was that any time there's a non-proceed termination of a request, that gets logged on the process side and then from an audit standpoint, it definitely logs if you want it to, but you can't be using the default log format from V2 and get anything useful out. It doesn't log enough fields to distinguish those cases.
Safe to say we'll dump that useless format in V4, it probably wasn't all that useful to keep it even now.
-- Scott
More information about the users
mailing list