InCommon MDQ configuration for attribute-filter and relying-party

Cooper, Robert A racooper at tamu.edu
Mon Jan 13 20:37:21 UTC 2025


Howdy!
I know this is pretty last-minute but I'm trying to get the InCommon MDQ configured.  There are a few parts I'm not sure about.

In the attribute-filter.xml, I have the AttributeFilterPolicy  for InCommon using 'InEntityGroup'.  Based on the documentation, This may need to be updated.  Specifically, I have:
    <AttributeFilterPolicy id="InCommonFederationDefaultRelease">
        <PolicyRequirementRule xsi:type="InEntityGroup" groupID="urn:mace:incommon" />
        <AttributeRule attributeID="eduPersonUniqueID">
            <PermitValueRule xsi:type="ANY" />
{...truncated...}
    </AttributeFilterPolicy>

In relying-party.xml, I also have an InEntityGroup rule for InCommon.
    <AttributeFilterPolicy id="InCommonFederationDefaultRelease">
        <PolicyRequirementRule xsi:type="InEntityGroup" groupID="urn:mace:incommon" />
        <AttributeRule attributeID="eduPersonUniqueID">
            <PermitValueRule xsi:type="ANY" />
{...truncated...}
    </AttributeFilterPolicy>

Without changing attribute-filter.xml or relying-party.xml, I cannot get any attributes to return when using an entityID that I know uses InCommon.  Are there examples of how to reconfigure these settings?  I've also tried looking at the document about releasing the R&S Bundle to all R&S SP's (https://spaces.at.internet2.edu/display/InCFederation/Research+and+Scholarship+IdP+Config) but it bounces back to the InCommon Federation Library home page.

Thanks,
RobertC

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250113/eb3f3ad7/attachment.htm>


More information about the users mailing list