<div><div><div dir="auto"><div dir="auto">Hi, Scott.</div></div><div dir="auto"><br></div><div dir="auto">I found the problem about MFA settings.</div><div dir="auto"><br></div><div dir="auto">I found out “input.removeSubcontext(resCtx)” is missing on the bottom of mfa-authn-config.xml</div><div dir="auto"><br></div><div dir="auto">My guess is as follows.Is this correct?</div><div dir="auto"><br></div><div dir="auto">If previous statement is missing, resolverContex generated in MFA Script affects main attribute resolution.</div></div><div dir="auto">For example, when only uid attribute was added to resolverContex without definition of “input.removeSubcontext(resCtx)”, only uid attribute is available in main attribute resolution.</div></div><div><div dir="auto"><br></div><div dir="auto">> Why do you think you need to resolve attributes during the MFA step? For what purpose?<br></div><div dir="auto"><br></div><div dir="auto"> I’d like authentication process to proceed to next flow depending on what specific attribute is.For example,only when otpUseFlag attribute is true, authentication process proceeds to next flow.</div><div dir="auto"><br></div><div><div><div><br><div class="gmail_quote"><div dir="ltr">On Mon, Feb 4, 2019 at 23:07 Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 2/4/19, 7:48 AM, "users on behalf of Noriyuki TAKEI" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:ntakei@sios.com" target="_blank">ntakei@sios.com</a>> wrote:<br>
> Is there any way to add an attribute to AttributeResolutionContext automatically<br>
> when new attributes are added to attributes-resolver.xml?<br>
<br>
That isn't what you want. You need to manipulate the MFA process to end up with a normalized principal name that matches whatever it is you need to feed into the "main" attribute resolution step later to get the results you need.<br>
<br>
The attribute resolution that happens inside the MFA logic has nothing to do with the "main" attribute lookup. You may not even need to be doing it. Why do you think you need to resolve attributes during the MFA step? For what purpose?<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div></div>
</div>
</div>
</div>