<div dir="ltr">Thanks Peter. <br><br>Interesting thing is ... my log was in DEBUG and there wasn't any "<saml2:AttributeStatement> ..... </saml2:AttributeStatement>" snippet there. <br>But when I replaced their supplied metadata with InCommon published one.... IDP started sending attribute to SPs. <br><br>So far, I used to know that it's IDP which actually make decision on sending / not sending attributes to SP but seems like SP has a big part here in this transaction as well. Never seen this before! <br><br> </div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Nov 25, 2019 at 10:45 AM Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Zico <<a href="mailto:mailzico@gmail.com" target="_blank">mailzico@gmail.com</a>> [2019-11-25 17:36]:<br>
> My initial issue is: I don't see any attribute being released from IDP side<br>
> OR it's inside `CipherData` snippet. Playing with "idp.encryption.optional<br>
> == true" and relying party isn't helping much to decipher that CipherData<br>
> snippet.<br>
<br>
That's not how you'd find out what your own IDP sends. You'd use:<br>
<br>
* aacli, to simulate what would be going out, and/or<br>
<br>
* your own log files, tuned as needed, e.g. by setting<br>
  <logger name="PROTOCOL_MESSAGE" level="DEBUG" /><br>
  and reloading your logging config (or waiting 10 min for it to<br>
  become active).<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature">Best,<br>Zico</div>