<div dir="ltr">The answers are yes and no.  You could, with application overrides, make your SP behave differently for each IdP you integrate with.  However, I&#39;m betting the problems here are at the IdP end especially if you&#39;re integrating via InCommon.  Unfortunately, you&#39;re going to have to slog it out with the IdP admins in this case.  Turning your logs up &amp; capturing the decrypted assertions will assist with identifying where the problems lie and assist with tweaks you may want to make to your attribute-map to accommodate the other IdP&#39;s &quot;specialness&quot;.  As for InCommon not releasing attributes, that&#39;s a new one.  Perhaps the IdP admin is expecting your SP to be tagged by InC as an R&amp;S SP which would trigger a filter policy automatically &amp; that&#39;s what they mean?<div>
<br></div><div>Dave</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Thu, Feb 6, 2014 at 3:14 PM, Ken Weiss <span dir="ltr">&lt;<a href="mailto:ken.weiss@ucop.edu" target="_blank">ken.weiss@ucop.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I&#39;m pretty sure the answer is &#39;no&#39;, but I wanted to ask the broader group<br>
just to be certain.<br>
<br>
If my Shibboleth SP works with 3 different IDPs, but doesn&#39;t work with 3<br>
others (failing in a different way for each of them), it&#39;s a pretty safe<br>
bet that the configuration issues are with the IDP, not my SP, right?<br>
<br>
I have one IDP that is returning two identical email addresses in the<br>
&#39;mail&#39; attribute. That&#39;s causing our application to error out, which we<br>
need to fix since email is a multi-valued attribute. But it&#39;s got nothing<br>
to do with my SP.<br>
<br>
I have one that isn&#39;t authorizing to my application correctly, which is<br>
almost certainly a result of the IDP not releasing the right attributes.<br>
<br>
And I have one that, for reasons that truly baffle me, reports that<br>
&quot;InCommon is not releasing the proper attributes.&quot; I have no idea what<br>
InCommon would have to do with this - all they do is deliver the metadata<br>
for my SP. Other than that, InCommon is not involved in the interaction,<br>
since I&#39;m no longer using InCommon&#39;s Discovery Service.<br>
<br>
Anyway, before I tell them all to look at their own IDP configuration, I<br>
thought it would be good to get a quick sanity check from some people that<br>
have actually run an IDP at some point in their life (unlike me...).<br>
Thanks!<br>
<br>
--Ken<br>
------------------------------------------------------------<br>
Ken Weiss                                 <a href="mailto:ken.weiss@ucop.edu">ken.weiss@ucop.edu</a><br>
UC Office of the President              <a href="tel:510-587-6311" value="+15105876311">510-587-6311</a> (office)<br>
California Digital Library              <a href="tel:916-905-6933" value="+19169056933">916-905-6933</a> (mobile)<br>
UC Curation Center<br>
415 20th Street, 4th Floor<br>
Oakland, CA 94612<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div>
</div>