<div dir="ltr"><span style="font-size:12.8px">Hi Gary,</span><div style="font-size:12.8px"><br></div><div style="font-size:12.8px">It is possible to suppress the user consent dialog for specific services. This provides for backwards compatibility with IdPv2's uApprove's services/services.blacklist settings, which is the behavior you wish to retain.</div><div style="font-size:12.8px"><br></div><div style="font-size:12.8px">The configuration is in the relying-party.xml file and in controlled by the p:postAuthenticationFlows="attribute-release" which is set in</div><div style="font-size:12.8px"><br></div><div style="font-size:12.8px">    <font face="monospace, monospace"><bean parent="Shibboleth.SSO" p:postAuthenticationFlows="attribute-release" /></font> and</div><div style="font-size:12.8px">    <font face="monospace, monospace"><bean parent="SAML2.SSO" p:postAuthenticationFlows="attribute-release" /></font><br><div class="gmail_extra"><br></div><div class="gmail_extra">So in your relying-party.xml add an RelyingPartyOverrides to turn off attribute-release as follows for each SP where you want to "blacklist" user consent.</div><div class="gmail_extra"><br></div><div class="gmail_extra"><div><code>    </code><code><</code><code>util:list</code> <code>id</code><code>=</code><code>"shibboleth.RelyingPartyOverrides"</code><code>></code></div><div><code><br></code></div><div><code>        </code><code><</code><code>bean</code> <code>parent</code><code>=</code><code>"RelyingPartyByName"</code></div><div><code>              </code><code>c:relyingPartyIds</code><code>=</code><code>"#{{'<a href="https://a.example.com/shibboleth%27," target="_blank">https://a.example.com/shibboleth',</a> '<a href="https://b.example.com/shibboleth%27%7D%7D" target="_blank">https://b.example.com/shibboleth'}}"</a></code><code>></code></div><div><code>            </code><code><</code><code>property</code> <code>name</code><code>=</code><code>"profileConfigurations"</code><code>></code></div><div><code>                </code><code><</code><code>list</code><code>></code></div><div><code>                    <bean parent="Shibboleth.SSO"/><br></code></div><div><code>                    <bean parent="SAML2.SSO" /></code></div><div><code>                </code><code></</code><code>list</code><code>></code></div><div><code>            </code><code></</code><code>property</code><code>></code></div><div><code>        </code><code></</code><code>bean</code><code>></code></div><div><code><br></code></div><div><code>    </code><code></</code><code>util:list</code><code>></code></div><div><code><font face="arial, helvetica, sans-serif"><br></font></code></div><div><font face="arial, helvetica, sans-serif">You will find an empty RelyingPartyOverrides container at the end of the default relying-party.xml file.</font></div><div><span style="font-family:monospace"><br></span></div><div><font face="arial, helvetica, sans-serif">Thanks,</font></div><div><font face="arial, helvetica, sans-serif">Terry.</font></div></div></div><div class="gmail_extra"><br>
<br><div class="gmail_quote">On Tue, Apr 12, 2016 at 2:08 PM, Lipscomb, Gary <span dir="ltr"><<a href="mailto:glipscomb@csu.edu.au" target="_blank">glipscomb@csu.edu.au</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-AU" link="#0563C1" vlink="#954F72">
<div>
<p class="MsoNormal">We are converting from v2 to v3 and wish to retain the v2 uApprove functionality whereby you can provide a blacklist of SP’s to which attribute release consent was not required since these are internal SP’s whereby consent has already been
 given by accepting the Universities’ ToU.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Is this possible in v3? I can’t find anything in the wiki.<u></u><u></u></p>
<p class="MsoNormal">If not is there a workaround with example code?<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Regards<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Gary<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Charles Sturt University<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<p style="FONT-SIZE:10pt;FONT-FAMILY:Arial"><a title="Charles Sturt University" href="http://www.csu.edu.au/" target="_blank"><img style="min-height:60px;WIDTH:210px" border="0" alt="Charles Sturt University" src="cid:csu-logo_74f41715-4530-4005-a285-3280d58d5de0.bmp"></a></p>
<p style="FONT-SIZE:8px;FONT-FAMILY:Arial,Helvetica,sans-serif;COLOR:#c42129">
|   ALBURY-WODONGA   |   BATHURST   |   CANBERRA   |   DUBBO   |   GOULBURN   |   MELBOURNE   |   ORANGE   |   PORT MACQUARIE   |   SYDNEY   |   WAGGA WAGGA   |</p>
<hr>
<span style="FONT-SIZE:9px;FONT-FAMILY:Arial,Helvetica,sans-serif;FONT-WEIGHT:bold">LEGAL NOTICE</span><br>
<span style="FONT-SIZE:9px;FONT-FAMILY:Arial,Helvetica,sans-serif">This email (and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute,
 take any action in reliance on it or disclose it to anyone. Any confidentiality is not waived or lost by reason of mistaken delivery. Email should be checked for viruses and defects before opening. Charles Sturt University (CSU) does not accept liability for
 viruses or any consequence which arise as a result of this email transmission. Email communications with CSU may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at CSU. The views
 expressed in this email are not necessarily those of CSU.</span>
<p style="FONT-SIZE:9px;FONT-FAMILY:Arial,Helvetica,sans-serif"><a style="COLOR:#c42129" href="http://www.csu.edu.au" target="_blank">Charles Sturt University in Australia</a> The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551;
 CRICOS Provider Number: 00005F (National)). TEQSA Provider Number: PV12018 <br>
<span style="FONT-SIZE:9px;FONT-FAMILY:Arial,Helvetica,sans-serif"></span></p>
<p style="FONT-SIZE:9px;FONT-FAMILY:Arial,Helvetica,sans-serif"><span style="FONT-SIZE:9px;FONT-FAMILY:Arial,Helvetica,sans-serif">Consider the environment before printing this email.</span>
</p>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div></div>