releasing AD group names

IAM David Bantz dabantz at alaska.edu
Fri Apr 8 21:30:22 UTC 2022


That’s the reasonable behavior I anticipated, but the service is not
protected by Shibboleth SP and they are adamant that no mapping or
transformation of SAML attribute values is possible.

On 08Apr2022 at 13:25:24, Bruce Timberlake via users <users at shibboleth.net>
wrote:

> That seems like something the SP should be able to do if they can't
> consume the attributes as they are natively released...
> https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065334474/TransformAttributeResolver
> comes to mind?
>
> Caveat - I am replying more on my understanding of how it should work than
> on actual implementation experience/knowledge :)
>
> --
> *Bruce Timberlake*
> *Sr Application Systems Administrator*, Identity and Access Management
> Services
> ITS - Information Assurance
> University of Michigan
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220408/6ebd481d/attachment.htm>


More information about the users mailing list