<br /><br /><span>On 24/02/12, <b class="name">Chad La Joie </b> &lt;lajoie@itumi.biz&gt; wrote:</span><blockquote cite="mid:CACTY7uBWgm6tPC-2369ScrOgSz_u2ei-bzxFZsZz_Zn21=h4Aw@mail.gmail.com" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain">Nope, not even that.  If the entitlement is stored in your directory<br />just look it up with the LDAP data connector and use the simple<br />attribute definition.  So, a pretty simple resolver config.</div></blockquote>Ah, ok cool. What happens if they have multiple entitlements (one for each SP they are entitled to)? How does the simple attribute model these?<br />-Keith<br /><blockquote cite="mid:CACTY7uBWgm6tPC-2369ScrOgSz_u2ei-bzxFZsZz_Zn21=h4Aw@mail.gmail.com" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain"><br /><br />Then you use the filter engine to release the entitlement for SP 1 to<br />SP 1, for SP 2 to SP 2, etc.<br /><br />On Fri, Feb 24, 2012 at 09:42, Keith Carr &lt;kecarr@sgul.ac.uk&gt; wrote:<br />&gt; So all I need to do is write some JavaScript within the eduPersonEntitlement<br />&gt; attribute definition in attribute-resolver.xml to pull out the relevant SP N<br />&gt; entitlement from LDAP?<br /><br /><br />-- <br />Chad La Joie<br />www.itumi.biz<br />trusted identities, delivered<br />--<br />To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br /></div></blockquote>