<div dir="ltr">Create/release a new attribute without scope (perhaps the underlying identifier you use to create ePUID); <br>do not name it eduPersonUniqueId though because it will not be!<div><br></div><div>David Bantz</div></div><br><div class="gmail_quote"><div dir="ltr">On Fri, Dec 14, 2018 at 12:24 PM Kurtz, Anna <<a href="mailto:anna.kurtz@sdstate.edu">anna.kurtz@sdstate.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US">
<div class="gmail-m_-6539695762322924634WordSection1">
<p class="MsoNormal">Hello,<u></u><u></u></p>
<p class="MsoNormal">We have recently released the eduPersonUniqueID to an SP. We set the ePUID to be scoped in the attribute resolver. We are on IdP 3.2.1<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">The SP that requires the ePUID is seeing the value as [id value]@[scope] and they do not know how to deal with the scope. They just need the [id value]. The SP is not able to make any changes to ignore the scope.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Is there a way in the attribute resolver or filter on our end to change how the ePUID is sent to just that one SP? We want to try and exclude the scope for them.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Thank you!<u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt">Anna </span><span style="font-size:10pt"><br>
<br>
</span><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>