<p dir="ltr">Hi Mike,</p>
<p dir="ltr">It looks as if the NAM IPD is sending all the group memberships from their local directory. They should be able to configure a role(s) that represent the two strings your looking for and inset it into the right saml attribute.</p>

<p dir="ltr">Someone over on the NetIQ forums will be able to help them. Also they should RTFM as they are pretty good.<br></p>
<div class="gmail_quote">On 03/10/2013 6:52 PM, &quot;Peter Schober&quot; &lt;<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>&gt; wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
* Mike Flynn &lt;<a href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; [2013-10-02 20:49]:<br>
&gt; That will not fly for my side of the application.  Just looking to<br>
&gt; figure out some rule on the IDP (or whatever config has to<br>
&gt; happen...) to send a value of say &#39;lyndaaccess&#39; / &#39;nolyndaaccess&#39; as<br>
&gt; the entitlement so that I can filter access based on the value.<br>
<br>
That (configuration details for that other product, whatever current<br>
name and vendor) is not something the Shibboleth community can help<br>
you with.<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>