<br><br><div class="gmail_quote">On Wed, Dec 5, 2012 at 9:56 AM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
* Nathan Mische &lt;<a href="mailto:nmische@gmail.com">nmische@gmail.com</a>&gt; [2012-12-05 15:46]:<br>
<div class="im">&gt; We currently have a Shibboleth 2.5 IdP instance running on Tomcat 6<br>
<br>
</div>Jfyi, no such version exists. The latest IdP version is 2.3.8.<br></blockquote><div><br>Ah, yes sorry 2.3.8. I&#39;ve also been doing a lot of work with our SPs which are 2.5.0.<br> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div class="im"><br>
&gt; I see that if we move to the external authentication login handler<br>
&gt; we should be able to attach the Tomcat principal to the httpRequest<br>
&gt; object we send back to the AuthenticationEngine, I&#39;m just not sure<br>
&gt; if it is possible to then query that principal&#39;s roles in an<br>
&gt; attribute resolver.<br>
<br>
</div>I&#39;m sure you can get at most anything in your container from within<br>
the attribute resolver,<br>
-peter<br></blockquote><div><br>Would this require a custom Java or do you think it could be done in the XML config?<br> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br>Thanks!<br>