<div dir="ltr"><div dir="ltr">On Thu, Feb 14, 2019 at 2:10 PM Melvin Lasky <<a href="mailto:melvin.lasky@manhattan.edu">melvin.lasky@manhattan.edu</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div style="overflow-wrap: break-word;"><div></div><div><AttributeFilterPolicy id="releaseForBannerApps" ><br>  <PolicyRequirementRule xsi:type="Requester" value="<a href="https://specific_banner_app_server.manhattan.edu" target="_blank">https://specific_banner_app_server.manhattan.edu</a>" /></div></div></blockquote><div> </div><div>If you register services via the CAS service registry, then the relying party ID will be _exactly_ the value sent to the IdP in the "service" CAS protocol parameter. I suspect that's the problem here given that the URL above has no path or query parts. Look at the traffic between your Banner apps and Shib using your browser's developer console to capture the exact service URL that's getting sent to Shib, then update your attribute filter rule accordingly.</div><div><br></div><div>Hope that helps,</div><div>Marvin</div><div><br></div></div></div>