<br /><br /><span>On 24/02/12, <b class="name">&quot;Cantor, Scott&quot; </b> &lt;cantor.2@osu.edu&gt; wrote:</span><blockquote cite="mid: &lt;BA63CEAE152A7742B854C678D9491383262DF015@CIO-KRC-D1MBX01.osuad.osu.edu" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain">&gt; Ah, ok cool. What happens if they have multiple entitlements (one for each<br />&gt; SP they are entitled to)? How does the simple attribute model these?<br /><br />They're all present. The filter engine can be used to limit release to just the ones that apply to a service. Changing the filter is a simple operation that can be done without significant effort or worrying about restarting the IdP, whereas changing the resolver really isn't.</div></blockquote>Yes, have made changes to the filter before and is relatively simple.<br />So if the entitlements are stored as a multi-valued attribute in LDAP it will create an eduPersonEntitlement attribute for each? Or give one eduPersonEntitlement attribute multiple values?<br />-Kieth<br /><blockquote cite="mid: &lt;BA63CEAE152A7742B854C678D9491383262DF015@CIO-KRC-D1MBX01.osuad.osu.edu" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain"><br /><br />-- Scott<br /><br />--<br />To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br /></div></blockquote>