Different Attribute Filters for different ResponderIds

Cantor, Scott cantor.2 at osu.edu
Wed Jun 7 09:24:19 EDT 2017


On 6/7/17, 7:13 AM, "users on behalf of Daniel Lutz" <users-bounces at shibboleth.net on behalf of daniel.lutz at switch.ch> wrote:

> To my knowledge, only a single Attribute Filter service is available (and
> configurable by a set of attribute filter policies), and it's not possible
> to define multiple Attribute Filter services and let the IdP choose the filter
> service to use depending on some criterion (e.g. the ResponderId).
> (And the "AttributeIssuer*" matching rules available in IdP 2 seem to
> have been deprecated in IdP 3.)

They just never got used. If there's a valid use case for them, keeping them shouldn't be a problem. Are they gone or just deprecated right now?

> May we need to define some kind of proxying Attribute Filter service, which
> calls a specific Attribute Filter service matching the criterion?

That would be a workaround, and is one reason we don't bother to overcomplicate this kind of thing, since you can actually substitute your own service implementations, but I doubt we have the necessary wiring exposed at this point.

If the rules are still working, I would just use them and please identify them for us in a bug request so we can get them cleaned up and undeprecated.

-- Scott




More information about the users mailing list