Attribute Consent -- Restrict by entityId
Joel Levin
joel.aaron.levin at gmail.com
Fri Feb 17 19:00:35 EST 2017
Not too sure I digested the info.
W.r.t attribute-consent --
1) we can allow for all SPs by default or
2) we can disallow for all SPs by default or
3) we can specify which SPs would require attribute-consent and which SPs
would not require attribute-consent (but that would mean listing all SP's
in relying-party.xml with individual RelyingPartyByName - which is not
ideal as many SPs)
Did I get above right?
On Fri, Feb 17, 2017 at 1:43 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > Based on testing -- When the " p:postAuthenticationFlows="attribute-
> > release" is commented out in the DefaultRelyingParty -- the IdP rejects
> > integrations unless it is explicitely listed in RelyingPartyByName.
>
> If you don't want a flow enabled, you remove the setting. You can't
> comment out the whole profile unless you're trying to disable it.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170217/79858897/attachment.html>
More information about the users
mailing list