<div dir="ltr">Hello Cantor,<div>Thank you for your reply, but you are saying attributes pulled from resolver:</div><div>Is that attribute-resolver.xml, configured for releasing attributes, in that case</div><div>i am releasing &#39;principal&#39; which contains &#39;permissions&#39; to SP. Is that right?</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Dec 1, 2014 at 8:36 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 12/1/14, 10:03 AM, &quot;Surinaidu Majji&quot; &lt;<a href="mailto:pioneer.suri@gmail.com">pioneer.suri@gmail.com</a>&gt; wrote:<br>
<br>
&gt;The above is the authentication process we are following for our<br>
&gt;application, Now we wanted to do the authorization, So i need two<br>
&gt;clarifications here.<br>
&gt;i) Do i need to prepare one more samlRequest like SAML Authorization<br>
&gt;Decision statement to send for idp again after authentication is done.<br>
<br>
</span>No.<br>
<span class=""><br>
&gt;or<br>
&gt;<br>
&gt;ii) As i mentioned in the step(2), Shall i get the authorization<br>
&gt;permission from our server and put it in the(login.getAttributes()) which<br>
&gt;is in the UserPrinciple(), to get it at the SP side and use the<br>
&gt;permissions to give the access to the user.<br>
<br>
</span>No.<br>
<br>
Peter answered your question several times.<br>
<br>
Attributes are pulled from the resolver and encoded into the SSO assertion<br>
and it&#39;s up to the SP to get them out and use them.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>