<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">The CAS protocol support components do, in fact, use the standard attribute filter.  The only catch is that there is no canonical entity ID, so the policy has to reference the URL of the service.</blockquote><div><br></div><div>An alternative if you're using the service registry: you can define the group and use a group-based filter expression in attribute-filter.xml.</div><div><br></div><div>M</div><div><br></div></div></div>