<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>Do I need to restart ShibD if I change the logging level?</span></div><div><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><div style="font-family: times new roman, new york, times, serif; font-size: 12pt;"><font size="2" face="Arial"><hr size="1"><b><span style="font-weight:bold;">From:</span></b> Peter Schober <peter.schober@univie.ac.at><br><b><span style="font-weight: bold;">To:</span></b> users@shibboleth.net<br><b><span style="font-weight: bold;">Sent:</span></b> Tuesday, October 4, 2011 9:22 AM<br><b><span style="font-weight: bold;">Subject:</span></b> Re: Logged attribute question<br></font><br>
* Mike Flynn <<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>> [2011-10-04 18:10]:<br>> So, from my side, I get no attributes from them. I have not changed<br>> any of my configs. My question is this: Does the transaction log<br>> show all attributes passed regardless of my current attribute<br>> policy? I seem to recall that it did as I had to do an update to my<br>> attribute policy for an Idp recently and before I added the<br>> attributes to my policy, I was able to see them in the tran log.<br><br>Attributes filtered out by the SP's attribute policy will only show up<br>in shibd.log IIRC, same for unmapped atteributes (those not in the<br>SP's attribute map).<br>For unmapped NameIDs you'd need to turn up shibd.logger to DEBUG, in<br>which case you'd see the complete decrypted assertion anyway, so<br>there'd be no guessing what's
included in the assertion or not.<br>-peter<br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div></div></div></body></html>