Attribute Filter Policy with multiple NOT

James Gross JamesGross at uncc.edu
Fri Mar 31 11:54:08 EDT 2017


Adam,
We use the following nesting succesfully:

*<PolicyRequirementRule xsi:type="NOT">*
*    <Rule xsi:type="OR">*
*        <Rule xsi:type="Requester" value="SPID1" />*
*        <Rule xsi:type="Requester" value="SPID2" />*
*        <Rule xsi:type="Requester" value="SPID3" />*
*    </Rule>*
*</PolicyRequirementRule>*

------------------------------
*James Gross* | Enterprise Application and CMS Developer (Enterprise Web
Services)

UNC Charlotte | Information Technology Services

9201 University City Blvd. | Charlotte, NC 28223

Phone: 704-687-0298 | Office: Kennedy 301-C39

jgross15 at uncc.edu | http://www.uncc.edu
------------------------------

If you are not the intended recipient of this transmission or a person
responsible for delivering it to the intended recipient, any disclosure,
copying, distribution, or other use of any of the information in this
transmission is strictly prohibited. If you have received this transmission
in error, please notify me immediately by reply e-mail or by telephone at
704-687-0298. Thank you.



On Fri, Mar 31, 2017 at 11:36 AM, Adam Portier <aportier at haverford.edu>
wrote:

> Good morning,
>
> I am working on an integration with an external SP for our college. Under
> our current filter policy, we release the same set of attributes to all SPs
> *except* one, which doesn't handle unexpected attributes in the release
> well. It looks something like this right now:
>
> <AttributeFilterPolicy id="default">
>
>         <PolicyRequirementRule xsi:type="NOT">
>             <Rule xsi:type="Requester" value="problem-sp.com" />
>         </PolicyRequirementRule>
> ...
>
> I the new SP I am working on integrating has very similar problems with
> unexpected attributes. Rather than changing the policy to explicitly list
> out every SP allowed to use it with an AND, I would like to extend the NOT
> to handle 2 SPs. Here is what I think should work, but is throwing an error
> in the logs.
>
> <AttributeFilterPolicy id="default">
>
>         <PolicyRequirementRule xsi:type="NOT">
>             <Rule xsi:type="Requester" value="problem-sp.com" />
>             <Rule xsi:type="Requester" value="problem-sp2.com" />
>         </PolicyRequirementRule>
> ...
>
> I have dug through the mailing list archives and could not find an answer
> to this problem. I have also reviewed the schema, and what I am doing
> should not be a violation (if I understand it correctly, which I likely do
> not). I have tried creating a nested set of PolicyRequirementRule blocks
> that either have multiple NOT rules inside an OR rule, or a NOT rule
> containing a single OR rule. Nothing has worked so far. If anyone has had
> success creating a filter policy that permits multiple NOT rules, I would
> appreciate some pointers.
>
> Thank you.
>
> --
> Adam Portier
> Linux Administrator
> IITS Core Technologies
> Haverford College
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170331/6af5f0d3/attachment.html>


More information about the users mailing list