<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>Thank you....appreciate the direction.</div><div><br></div><div>1 more question -- and I may have this licked.</div><div><br></div><div>Can an id have 2 AdminFlows? Example:<br></div><div><br></div><div><br></div><div><bean parent="shibboleth.AdminFlow"<br> c:id="<a href="http://shibboleth.net/ns/profiles/status">http://shibboleth.net/ns/profiles/status</a>"<br> p:loggingId="%{idp.service.logging.status:Status}"<br> p:policyName="%{idp.status.accessPolicy:AccessByIPAddress}" /></div><div><br></div><div><bean parent="shibboleth.AdminFlow"<br> c:id="<a href="http://shibboleth.net/ns/profiles/status">http://shibboleth.net/ns/profiles/status</a>"</div><div> p:authenticated="true"<br></div><div> p:loggingId="%{idp.service.logging.status:Status}"<br> p:policyName="%{idp.reload.accessPolicy:AccessByUser}" /</div></div></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Apr 30, 2019 at 5:14 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">The default value for the resolveAttributes setting on administrative flows is false, so I imagine the logs will show it's not doing any attribute lookup at all and that would prevent any checks from succeeding. The documentation always links to the javadocs for the beans of the types these files contain, you have to look at those to know what settings are available and what their defaults are.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>