<div dir="ltr">Scott described proper behavior and coordination between IdP and SP. However there are intransigent SPs that expect the SAML to express something in the SP's made-up name space, such as a particular name or friendlyName in the assertion. You can (mis-)use the IdP to send something like they expect (after admonishing the SP and failing to get them to cast the scales from their eyes) by adding an attribute with non-standard AttributeEncoder in the attribute-resolver.mxl using the name and/or friendlyName they require, and releasing that attribute to the miscreant SP in attribute-filter.xml. <div><br></div><div>David Bantz</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Mar 29, 2017 at 8:09 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 3/29/17, 12:06 PM, "users on behalf of Mary Wiegand" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:mwiegand@bastyr.edu">mwiegand@bastyr.edu</a>> wrote:<br>
<br>
> Has anyone run into an issue where they needed ldap attributes to show up as something else entirely to the SP?<br>
<br>
</span>The SP doesn't see any LDAP attributes, it sees SAML, and only through a mapping layer that's entirely up to the SP. In other words, this is how it works, already.<br>
<span class=""><br>
> I’m expecting that I need to map my attribute in the filter so that is displays as what the SP needs to see,<br>
<br>
</span>If you're talking about the IdP, no. You have nothing to do with it.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a></font></span></blockquote></div><br></div>