<div dir="ltr"><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><font face="courier new, monospace">Jeffrey E. Crawford<br>ITS Application Administrator (IdM)<br>831-459-4365<br><a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a></font><div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">Both pilots and IT professionals require training and currency before charging into clouds!<br></font></div><div><font face="courier new, monospace">---------------------------------------</font></div></div></div></div>
<br><div class="gmail_quote">On Fri, Jan 29, 2016 at 1:54 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="">> So something like eduGain = (!registerd-by-incommon) | (<br>
> !local:metadata:group)<br>
<br>
</span>Basically. I guess I was thinking more like you just make that the default behavior and don't really need to call it out. It's the others you'd override.<br></blockquote><div><br><div class="gmail_default" style="font-family:courier new,monospace;display:inline">Okay so if in the relying-party.xml file you specify the nameIDFormatPrecedence, that doesn't apply by default to the override if it is omitted (meaning the override goes back to the default precedence, if nameIDFormatPrecedence is not in the override section definition.<br></div></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<span class=""><br>
> Since going to v3 I've been collecting them into a single metadata file, but not<br>
> all of them yet. Is using urn:mace:incommon really that big of a problem?<br>
> Seems more "exact" to me.<br>
<br>
</span>It's fine until it totally breaks I guess. Point is, "registered by InCommon" is the exact rule you're looking for if that's what you're trying to apply a rule to. "Contained in InCommon group" doesn't really mean anything once eduGain hits (I don't think?), and won't work at all outside of the aggregate.<br>
<div class=""><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div></blockquote></div><br></div></div>