library-walk-in

Peter Schober peter.schober at univie.ac.at
Tue Feb 26 11:48:05 EST 2019


* Peter Schober <peter.schober at univie.ac.at> [2019-02-26 17:44]:
> Am I missing something? Or should I create one rule specific to the
> surrogate user account and add DenyValueRules for all attributes the
> IDP is likely to release?

Even then persistent NameIDs would still be released based on
NameIDFormat elements in metadata (since not releasing the underlying
attribute will not prevent releasing the derived NameID), and
overriding them would require enumerating SPs.

-peter


More information about the users mailing list