<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000"><div>more abbreviated file:<br></div><div>&lt;?xml version="1.0" encoding="UTF-8"?&gt;<br>&lt;afp:AttributeFilterPolicyGroup id="ShibbolethFilterPolicy"<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; xmlns:afp="urn:mace:shibboleth:2.0:afp" xmlns:basic="urn:mace:shibboleth:2.0:afp:mf:basic" <br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; xmlns:saml="urn:mace:shibboleth:2.0:afp:mf:saml" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" <br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; xsi:schemaLocation="urn:mace:shibboleth:2.0:afp classpath:/schema/shibboleth-2.0-afp.xsd<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; urn:mace:shibboleth:2.0:afp:mf:basic classpath:/schema/shibboleth-2.0-afp-mf-basic.xsd<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; urn:mace:shibboleth:2.0:afp:mf:saml classpath:/schema/shibboleth-2.0-afp-mf-saml.xsd"&gt;<br></div><div><br></div><div>&nbsp;&nbsp;&nbsp; &lt;afp:AttributeFilterPolicy id="releaseSpecificAttributes"&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PolicyRequirementRule xsi:type="basic:ANY"/&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:AttributeRule attributeID="eduPersonAffiliation"&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;afp:PermitValueRule xsi:type="basic:OR" &gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="faculty" ignoreCase="true"/&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="student" ignoreCase="true"/&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="staff" ignoreCase="true" /&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="alum" ignoreCase="true" /&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="member" ignoreCase="true" /&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="affiliate" ignoreCase="true" /&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="employee" ignoreCase="true" /&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;basic:Rule xsi:type="basic:AttributeValueString" value="library-walk-in" ignoreCase="true" /&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:PermitValueRule&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeRule&gt;<br>&nbsp;&nbsp;&nbsp; &lt;/afp:AttributeFilterPolicy&gt;<br><br>&lt;/afp:AttributeFilterPolicyGroup&gt;<br></div><div><br></div><div><br></div><div><br></div><div>same error message :(<br></div><div><br></div><div>14:33:48.233 - INFO [edu.internet2.middleware.shibboleth.common.config.BaseService:180] - shibboleth.AttributeResolver service loaded new configuration<br>14:33:48.237 - INFO [edu.internet2.middleware.shibboleth.common.config.BaseService:158] - Loading new configuration for service shibboleth.AttributeFilterEngine<br>14:33:48.253 - INFO [edu.internet2.middleware.shibboleth.common.config.attribute.filtering.AttributeFilterPolicyBeanDefinitionParser:72] - Parsing configuration for attribute filter policy releaseSpecificAttributes<br>14:33:48.266 - ERROR [edu.internet2.middleware.shibboleth.common.config.BaseService:188] - Configuration was not loaded for shibboleth.AttributeFilterEngine service, error creating components.&nbsp; The root cause of this error was: org.springframework.beans.factory.BeanCreationException: RuleReference elements within an AND rule are not supported<br></div><div><br></div><div><br></div><hr id="zwchr"><div style="color:#000;font-weight:normal;font-style:normal;text-decoration:none;font-family:Helvetica,Arial,sans-serif;font-size:12pt;" data-mce-style="color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;"><b>From: </b>"Paul Hethmon" &lt;paul.hethmon@clareitysecurity.com&gt;<br><b>To: </b>"Shib Users" &lt;users@shibboleth.net&gt;<br><b>Sent: </b>Monday, July 1, 2013 2:27:53 PM<br><b>Subject: </b>Re: attribute filter rule "PermitValueRule" not working<br><div><br></div><div>One thing to try is to remove all the rules in attribute-filter.xml and then slowly add them in until you get the error message. Your file was pretty small, it wouldn't take long.</div><div><br></div><div>Paul</div><div><br></div><div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt" data-mce-style="font-family: Calibri; font-size: 11pt; text-align: left; color: black; border-bottom: medium none; border-left: medium none; padding-bottom: 0in; padding-left: 0in; padding-right: 0in; border-top: #b5c4df 1pt solid; border-right: medium none; padding-top: 3pt;"><span style="font-weight:bold" data-mce-style="font-weight: bold;">From: </span>Kent Nasveschuk &lt;<a href="mailto:knasveschuk@mbl.edu" target="_blank" data-mce-href="mailto:knasveschuk@mbl.edu">knasveschuk@mbl.edu</a>&gt;<br> <span style="font-weight:bold" data-mce-style="font-weight: bold;">Reply-To: </span>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net" target="_blank" data-mce-href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br> <span style="font-weight:bold" data-mce-style="font-weight: bold;">Date: </span>Monday, July 1, 2013 2:21 PM<br> <span style="font-weight:bold" data-mce-style="font-weight: bold;">To: </span>Shibboleth Users &lt;<a href="mailto:users@shibboleth.net" target="_blank" data-mce-href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br> <span style="font-weight:bold" data-mce-style="font-weight: bold;">Subject: </span>Re: attribute filter rule "PermitValueRule" not working<br></div><div><br></div><div><div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000" data-mce-style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000;"><div>I just got 2.3.7 running, I can try on 2.4 but won't be for a while. I have a way around for my purposes right now, but that would sure come in handy.<br></div><div><br></div><div>I also tried "DenyValueRule", didn't work either, different error message. I only have 1 value to exclude, so it would be simpler to to use that.<br></div><div><br></div><div>Will keep hunting...<br></div><div><br></div><hr id="zwchr"><div style="color:#000;font-weight:normal;font-style:normal;text-decoration:none;font-family:Helvetica,Arial,sans-serif;font-size:12pt;" data-mce-style="color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;"><b>From: </b>"Scott Cantor" &lt;<a href="mailto:cantor.2@osu.edu" target="_blank" data-mce-href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt;<br> <b>To: </b>"Shib Users" &lt;<a href="mailto:users@shibboleth.net" target="_blank" data-mce-href="mailto:users@shibboleth.net">users@shibboleth.net</a>&gt;<br> <b>Sent: </b>Monday, July 1, 2013 1:44:36 PM<br> <b>Subject: </b>RE: attribute filter rule "PermitValueRule" not working<br><div><br></div>&gt; I don't see where the problem is.<br><div><br></div>I have to think that's not the file it's really using, or there's a second filter policy file configured.<br><div><br></div>Or I suppose there's some weird config parsing issue, so if you can reproduce on 2.4, we can certainly take a bug report if that same file produces that error.<br><div><br></div>-- Scott<br><div><br></div>--<br> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" data-mce-href="mailto:users-unsubscribe@shibboleth.net"> users-unsubscribe@shibboleth.net</a><br></div><div><br></div></div></div></div><br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div><div><br></div></div></body></html>