<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>Thanks, Rowan. &nbsp;They got on the forum and got the answer so we are all set.</span></div><div><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <hr size="1">  <font size="2" face="Arial"> <b><span style="font-weight:bold;">From:</span></b> Rowan Truscott &lt;rowan@truscott.net.au&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Thursday, October 3, 2013 2:01 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: Novell Netiq - Anyone have any experience with this IDP?<br> </font> </div> <div class="y_msg_container"><br><div id="yiv6667554043"><div><div dir="ltr">Hi
 Mike,</div>
<div dir="ltr">It looks as if the NAM IPD is sending all the group memberships from their local directory. They should be able to configure a role(s) that represent the two strings your looking for and inset it into the right saml attribute.</div>

<div dir="ltr">Someone over on the NetIQ forums will be able to help them. Also they should RTFM as they are pretty good.<br clear="none"></div>
<div class="yiv6667554043yqt9747980138" id="yiv6667554043yqt35448"><div class="yiv6667554043gmail_quote">On 03/10/2013 6:52 PM, "Peter Schober" &lt;<a rel="nofollow" shape="rect" ymailto="mailto:peter.schober@univie.ac.at" target="_blank" href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>&gt; wrote:<br clear="none"><blockquote class="yiv6667554043gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
* Mike Flynn &lt;<a rel="nofollow" shape="rect" ymailto="mailto:shibbolethlynda@yahoo.com" target="_blank" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; [2013-10-02 20:49]:<br clear="none">
&gt; That will not fly for my side of the application. &nbsp;Just looking to<br clear="none">
&gt; figure out some rule on the IDP (or whatever config has to<br clear="none">
&gt; happen...) to send a value of say 'lyndaaccess' / 'nolyndaaccess' as<br clear="none">
&gt; the entitlement so that I can filter access based on the value.<br clear="none">
<br clear="none">
That (configuration details for that other product, whatever current<br clear="none">
name and vendor) is not something the Shibboleth community can help<br clear="none">
you with.<br clear="none">
-peter<br clear="none">
--<br clear="none">
To unsubscribe from this list send an email to <a rel="nofollow" shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br clear="none">
</blockquote></div></div></div></div><br><div class="yqt9747980138" id="yqt53374">--<br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div><br><br></div> </div> </div>  </div></body></html>