Azure & IdP v5.1.3

Cantor, Scott cantor.2 at osu.edu
Thu Nov 7 13:07:32 UTC 2024


List please, which is what Reply-To is set to.

> The problem may be with the REGEXP.

The problem is with your metadata by definition, that's what the filter rule removing the value does. Once the value is gone, c14n is impossible, it doesn't matter what the subsequrnt 

> idp.c14.saml.proxy.regex.for.principal
> =^(.+)@NAME_SERVICE\.DOMAIN\.ORGANIZATION\.br$" 

That is not a setting we define in the IdP (that I recognize anyway) and I've no idea what it's doing, but it isn't relevant to an attribute filter rule enforcing scoping based on metadata.

The filter rule doesn't have any configuration settings at all, it's implicit: Check attribute values are scoped and that the scope matches the metadata extension in the issuer's metadata.

-- Scott




More information about the users mailing list