<div dir="ltr"><div class="gmail_default" style="font-family:'courier new',monospace">If we take away the entry:</div><div class="gmail_default"><div class="gmail_default"><font face="courier new, monospace"> <rp:RelyingParty id="urn:mace:incommon"</font></div>
<div class="gmail_default"><font face="courier new, monospace"> provider="urn:mace:incommon:<a href="http://ucsc.edu">ucsc.edu</a>"</font></div><div class="gmail_default"><font face="courier new, monospace"> defaultSigningCredentialRef="IdPCredential"></font></div>
<div class="gmail_default"><font face="courier new, monospace"> <rp:ProfileConfiguration xsi:type="saml:ShibbolethSSOProfile" /></font></div><div class="gmail_default"><font face="courier new, monospace"> <rp:ProfileConfiguration xsi:type="saml:SAML1AttributeQueryProfile" /></font></div>
<div class="gmail_default"><font face="courier new, monospace"> <rp:ProfileConfiguration xsi:type="saml:SAML1ArtifactResolutionProfile" /></font></div><div class="gmail_default"><font face="courier new, monospace"> <rp:ProfileConfiguration xsi:type="saml:SAML2SSOProfile" /></font></div>
<div class="gmail_default"><font face="courier new, monospace"> <rp:ProfileConfiguration xsi:type="saml:SAML2AttributeQueryProfile" /></font></div><div class="gmail_default"><font face="courier new, monospace"> <rp:ProfileConfiguration xsi:type="saml:SAML2ArtifactResolutionProfile" /></font></div>
<div class="gmail_default"><font face="courier new, monospace"> </rp:RelyingParty></font></div><div style="font-family:'courier new',monospace"><br></div><div style="font-family:'courier new',monospace">
Then and rely on (Defaults used):</div><div><div><font face="courier new, monospace"> <rp:DefaultRelyingParty provider="urn:mace:incommon:<a href="http://ucsc.edu">ucsc.edu</a>"</font></div><div><font face="courier new, monospace"> defaultSigningCredentialRef="IdPCredential"></font></div>
<div style="font-family:'courier new',monospace">.</div></div><div style="font-family:'courier new',monospace">.</div><div style="font-family:'courier new',monospace">.</div><div style="font-family:'courier new',monospace">
</rp:DefaultRelyingParty></div><div style="font-family:'courier new',monospace"><br></div><div style="font-family:'courier new',monospace">attribute filters stop working, We are using 2.4.0</div>
</div></div><div class="gmail_extra"><br clear="all"><div><div dir="ltr"><font face="courier new, monospace">Jeffrey E. Crawford<br>ITS Application Administrator (IdM)<br>831-459-4365<br><a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a></font><div>
<font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">Both pilots and IT professionals require training and currency before charging into clouds!<br></font></div><div><font face="courier new, monospace">---------------------------------------</font></div>
</div></div>
<br><br><div class="gmail_quote">On Mon, Mar 31, 2014 at 9:55 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="">On 3/31/14, 12:30 PM, "Jeffrey Crawford" <<a href="mailto:jeffreyc@ucsc.edu">jeffreyc@ucsc.edu</a>> wrote:<br>
><br>
>However we noticed that for entity id's were we didn't have a relying<br>
>party entry, but were allowed to login because they were caught in the<br>
>DefaultRelyingParty, the filters we defined stopped<br>
> working if we used the AttributeRequesterString in the<br>
>AttributeFilterPolicy.<br>
<br>
</div>That's not the case, so you're misinterpreting something.<br>
<div class=""><br>
>Is there a reason why AttributeFilterPolicys AttributeRequesterString<br>
>would ignore the entity ID and not apply filters if using<br>
>DefaultRelyingParty as opposed to RelyingParty.<br>
<br>
</div>They have literally nothing to do with each other, there's no relationship<br>
between the two designations.<br>
<br>
Whatever you observed is not a bug I have any recollection of, but I<br>
couldn't say for sure other than that all versions of the IdP going back<br>
to certainly 2.2 or so when I first ran it definitely support this fine. I<br>
use it every day that way.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br></div>