InCommon MDQ configuration for attribute-filter and relying-party
Cooper, Robert A
racooper at tamu.edu
Mon Jan 13 20:37:21 UTC 2025
Howdy!
I know this is pretty last-minute but I'm trying to get the InCommon MDQ configured. There are a few parts I'm not sure about.
In the attribute-filter.xml, I have the AttributeFilterPolicy for InCommon using 'InEntityGroup'. Based on the documentation, This may need to be updated. Specifically, I have:
<AttributeFilterPolicy id="InCommonFederationDefaultRelease">
<PolicyRequirementRule xsi:type="InEntityGroup" groupID="urn:mace:incommon" />
<AttributeRule attributeID="eduPersonUniqueID">
<PermitValueRule xsi:type="ANY" />
{...truncated...}
</AttributeFilterPolicy>
In relying-party.xml, I also have an InEntityGroup rule for InCommon.
<AttributeFilterPolicy id="InCommonFederationDefaultRelease">
<PolicyRequirementRule xsi:type="InEntityGroup" groupID="urn:mace:incommon" />
<AttributeRule attributeID="eduPersonUniqueID">
<PermitValueRule xsi:type="ANY" />
{...truncated...}
</AttributeFilterPolicy>
Without changing attribute-filter.xml or relying-party.xml, I cannot get any attributes to return when using an entityID that I know uses InCommon. Are there examples of how to reconfigure these settings? I've also tried looking at the document about releasing the R&S Bundle to all R&S SP's (https://spaces.at.internet2.edu/display/InCFederation/Research+and+Scholarship+IdP+Config) but it bounces back to the InCommon Federation Library home page.
Thanks,
RobertC
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250113/eb3f3ad7/attachment.htm>
More information about the users
mailing list