<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Sep 15, 2016 at 4:23 PM, Gould, Samuel <span dir="ltr"><<a href="mailto:Samuel.Gould@sdstate.edu" target="_blank">Samuel.Gould@sdstate.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><p class="MsoNormal">  - According to the SAML Tracer FF plugin, no `<AttributeStatement>' is sent...<u></u><u></u></p>
<p class="MsoNormal">  - Verified that our IdP provides correct SAML assertions in response to this<br></p><p class="MsoNormal"><u></u></p>
<p class="MsoNormal">    SP (determined with SAML Tracer FF plugin)<u></u><u></u></p>
<p class="MsoNormal"></p></blockquote></div><br>You may consider an authentication statement without attribute statement to be "correct"</div><div class="gmail_extra">and it may be all that's needed by some SP's, but if your SP requires a value of the attribute</div><div class="gmail_extra">eduPersonPrincipalName, you SAML assertion is at least incomplete!</div><div class="gmail_extra"><br></div><div class="gmail_extra">Log file idp-process.log should have details of the interaction; increase logging level to debug</div><div class="gmail_extra">if there isn't enough to identify why no attributes are being released.</div><div class="gmail_extra"><br></div><div class="gmail_extra">Based on my experience, look first to match of your release policy to the entityID of the SP </div><div class="gmail_extra">(if you're not releasing the same attribute bundle to every SP) - including http/https and</div><div class="gmail_extra">presence or absence of trailing / in the names.</div><div class="gmail_extra"><br></div><div class="gmail_extra">David Bantz</div></div>