<div dir="ltr"><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><font face="courier new, monospace">Jeffrey E. Crawford<br>ITS Application Administrator (IdM)<br>831-459-4365<br><a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a></font><div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">Both pilots and IT professionals require training and currency before charging into clouds!<br></font></div><div><font face="courier new, monospace">---------------------------------------</font></div></div></div></div>
<br><div class="gmail_quote">On Fri, Jan 29, 2016 at 1:54 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="">> ​So something like eduGain = (!registerd-by-incommon) | (​<br>
> !local:metadata:group)<br>
<br>
</span>Basically. I guess I was thinking more like you just make that the default behavior and don't really need to call it out. It's the others you'd override.<br></blockquote><div><br><div class="gmail_default" style="font-family:courier new,monospace;display:inline">​Okay so if in the relying-party.xml file you specify the ​nameIDFormatPrecedence, that doesn't apply by default to the override if it is omitted (meaning the override goes back to the default precedence, if nameIDFormatPrecedence is not in the override section definition.<br></div></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<span class=""><br>
> Since going to v3 I've been collecting them into a single metadata file, but not<br>
> all of them yet. Is using urn:mace:incommon really that big of a problem?<br>
> Seems more "exact" to me.<br>
<br>
</span>It's fine until it totally breaks I guess. Point is, "registered by InCommon" is the exact rule you're looking for if that's what you're trying to apply a rule to. "Contained in InCommon group" doesn't really mean anything once eduGain hits (I don't think?), and won't work at all outside of the aggregate.<br>
<div class=""><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div></blockquote></div><br></div></div>