Exclude specific EntityID from attribute-match policy requirement rule?

Cantor, Scott cantor.2 at osu.edu
Tue Feb 15 12:43:38 UTC 2022


On 2/14/22, 9:02 PM, "users on behalf of Mak, Steve" <users-bounces at shibboleth.net on behalf of makst at upenn.edu> wrote:

>    You should just setup a separate filter rule to DENY those attributes to that EntityID. Deny rules always
> trump Allow rules.

That certainly also works, but also can create confusion later if you try and create an additive rule for that SP in some way later, and you end up wondering why it's not working. For some people (ok, for me), just having additive rules tends to be more understandable, but use whichever way is most clear.

The most important thing really is, don't use per-SP filter rules at all. Set up rules based on metadata tagging, and then just tag the metadata to release attributes. Works more cleanly and is faster than having dozens of filter policies.

-- Scott




More information about the users mailing list