Azure & IdP v5.1.3
Cantor, Scott
cantor.2 at osu.edu
Thu Nov 7 13:07:32 UTC 2024
List please, which is what Reply-To is set to.
> The problem may be with the REGEXP.
The problem is with your metadata by definition, that's what the filter rule removing the value does. Once the value is gone, c14n is impossible, it doesn't matter what the subsequrnt
> idp.c14.saml.proxy.regex.for.principal
> =^(.+)@NAME_SERVICE\.DOMAIN\.ORGANIZATION\.br$"
That is not a setting we define in the IdP (that I recognize anyway) and I've no idea what it's doing, but it isn't relevant to an attribute filter rule enforcing scoping based on metadata.
The filter rule doesn't have any configuration settings at all, it's implicit: Check attribute values are scoped and that the scope matches the metadata extension in the issuer's metadata.
-- Scott
More information about the users
mailing list