<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Sorry if this is in the wiki, but I couldn&#8217;t find an example.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">I am working with a SP that can only look at a single attribute for their permission scheme. I&#8217;m trying to figure out the options available to me on the IdP side to facilitate this.&nbsp; I&#8217;d like to attempt to keep as much of the work as possible,
 for looking at attribute values and making decisions, on the SP&#8217;s side.&nbsp; <o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Ideally, the SP would be able to look at two attributes, one for the user&#8217;s org unit and another for the user&#8217;s school code and figure out the permissions on their side.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Is it possible, using the out-of-box Shibboleth IdP v2, to create a new attribute that is populated from LDAP attribute values conditionally based on other LDAP attributes for the user that is authenticating?&nbsp; I know that I can create a
 static attribute with custom values and then create multiple release policies that can check LDAP attributes for particular values, and only permit the release of certain values from the new static attribute but this is not something I think I would like to
 maintain on my side.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Ex:<o:p></o:p></p>
<p class="MsoNormal">If a user is a faculty/staff member (determined from their affiliation LDAP attribute), then the new attribute would contain the values from their org unit LDAP attribute.<o:p></o:p></p>
<p class="MsoNormal">If a user is a student(determined from their affiliation LDAP attribute), then the new attribute would contain values from their associated school code or &#8220;student&#8221;&#43;schoolCode.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Thanks for any help!<o:p></o:p></p>
<p class="MsoNormal">Kyle<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>