<div dir="ltr"><div class="gmail_default" style="font-family:&#39;courier new&#39;,monospace">If we take away the entry:</div><div class="gmail_default"><div class="gmail_default"><font face="courier new, monospace">    &lt;rp:RelyingParty id=&quot;urn:mace:incommon&quot;</font></div>
<div class="gmail_default"><font face="courier new, monospace">                  provider=&quot;urn:mace:incommon:<a href="http://ucsc.edu">ucsc.edu</a>&quot;</font></div><div class="gmail_default"><font face="courier new, monospace">                  defaultSigningCredentialRef=&quot;IdPCredential&quot;&gt;</font></div>
<div class="gmail_default"><font face="courier new, monospace">       &lt;rp:ProfileConfiguration xsi:type=&quot;saml:ShibbolethSSOProfile&quot; /&gt;</font></div><div class="gmail_default"><font face="courier new, monospace">       &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML1AttributeQueryProfile&quot; /&gt;</font></div>
<div class="gmail_default"><font face="courier new, monospace">       &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML1ArtifactResolutionProfile&quot; /&gt;</font></div><div class="gmail_default"><font face="courier new, monospace">       &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2SSOProfile&quot; /&gt;</font></div>
<div class="gmail_default"><font face="courier new, monospace">       &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2AttributeQueryProfile&quot; /&gt;</font></div><div class="gmail_default"><font face="courier new, monospace">       &lt;rp:ProfileConfiguration xsi:type=&quot;saml:SAML2ArtifactResolutionProfile&quot; /&gt;</font></div>
<div class="gmail_default"><font face="courier new, monospace">    &lt;/rp:RelyingParty&gt;</font></div><div style="font-family:&#39;courier new&#39;,monospace"><br></div><div style="font-family:&#39;courier new&#39;,monospace">
Then and rely on (Defaults used):</div><div><div><font face="courier new, monospace">    &lt;rp:DefaultRelyingParty provider=&quot;urn:mace:incommon:<a href="http://ucsc.edu">ucsc.edu</a>&quot;</font></div><div><font face="courier new, monospace">                            defaultSigningCredentialRef=&quot;IdPCredential&quot;&gt;</font></div>
<div style="font-family:&#39;courier new&#39;,monospace">.</div></div><div style="font-family:&#39;courier new&#39;,monospace">.</div><div style="font-family:&#39;courier new&#39;,monospace">.</div><div style="font-family:&#39;courier new&#39;,monospace">
    &lt;/rp:DefaultRelyingParty&gt;</div><div style="font-family:&#39;courier new&#39;,monospace"><br></div><div style="font-family:&#39;courier new&#39;,monospace">attribute filters stop working, We are using 2.4.0</div>
</div></div><div class="gmail_extra"><br clear="all"><div><div dir="ltr"><font face="courier new, monospace">Jeffrey E. Crawford<br>ITS Application Administrator (IdM)<br>831-459-4365<br><a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a></font><div>
<font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">Both pilots and IT professionals require training and currency before charging into clouds!<br></font></div><div><font face="courier new, monospace">---------------------------------------</font></div>
</div></div>
<br><br><div class="gmail_quote">On Mon, Mar 31, 2014 at 9:55 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="">On 3/31/14, 12:30 PM, &quot;Jeffrey Crawford&quot; &lt;<a href="mailto:jeffreyc@ucsc.edu">jeffreyc@ucsc.edu</a>&gt; wrote:<br>
&gt;<br>
&gt;However we noticed that for entity id&#39;s were we didn&#39;t have a relying<br>
&gt;party entry, but were allowed to login because they were caught in the<br>
&gt;DefaultRelyingParty, the filters we defined stopped<br>
&gt; working if we used the AttributeRequesterString in the<br>
&gt;AttributeFilterPolicy.<br>
<br>
</div>That&#39;s not the case, so you&#39;re misinterpreting something.<br>
<div class=""><br>
&gt;Is there a reason why AttributeFilterPolicys AttributeRequesterString<br>
&gt;would ignore the entity ID and not apply filters if using<br>
&gt;DefaultRelyingParty as opposed to RelyingParty.<br>
<br>
</div>They have literally nothing to do with each other, there&#39;s no relationship<br>
between the two designations.<br>
<br>
Whatever you observed is not a bug I have any recollection of, but I<br>
couldn&#39;t say for sure other than that all versions of the IdP going back<br>
to certainly 2.2 or so when I first ran it definitely support this fine. I<br>
use it every day that way.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br></div>