activationConditions using an attribute value

Marco Naimoli marco.naimoli at
Wed Jul 11 11:53:37 EDT 2018

Thank you Peter. My configuration is:

<!-- This was created just for testing purposes -->
     <DataConnector id="testStaticAttribute" xsi:type="Static">
         <Attribute id="attribute1">

<AttributeDefinition id="myTest" xsi:type="Simple" 
sourceAttributeID="attribute1" activationConditionRef="isInternal">
     <Dependency ref="testStaticAttribute" />
     <AttributeEncoder xsi:type="SAML2String" 
name="https://my.static.attr"  friendlyName="mytest" />

<!-- when a user has employeeType='external' then 
unipdEmployeeType="NO", otherwise unipdEmployeeType="OK" -->
<AttributeDefinition id="unipdEmployeeType" xsi:type="Mapped" 
sourceAttributeID="employeeType" dependencyOnly="true">
     <Dependency ref="openldap_activation" />

     <bean id="internalUser" 
         <property name="attributeValueMap">
                 <entry key="unipdEmployeeType">

<!-- I'm using the "OR" condition because my plans are to add other SPs 
to the list -->
     <bean id="permitRP" parent="shibboleth.Conditions.OR">
                 <bean parent="shibboleth.Conditions.RelyingPartyId" 
c:_0="" />

<!-- the condition is: when the unipdEmployeeType="OK" OR the SP is one 
of the list, then proceed -->
     <bean id="isInternal" parent="shibboleth.Conditions.OR">
                 <bean parent="permitRP"/>
                 <bean parent="internalUser"/>

Everything works fine when the SP is 
(so one of the two conditions are met), I see the correct value of myTest
using aacli; otherwise it doesn't work, myTest has no value and in 
idp-process.log I see:

Resolver plugin 'myTest': activation criteria not met, nothing to do

Thank you

Il 11/07/2018 17:00, Peter Schober ha scritto:
> * Marco Naimoli <marco.naimoli at> [2018-07-11 16:50]:
>> Before going on with questions, I'd like to know if what I'm trying
>> to do is possible or not
> Yes (as far as that can besaid based on the details you have provided
> so far).
> -peter

More information about the users mailing list