<div dir="ltr"><div dir="ltr">On Mon, Jan 13, 2020 at 2:19 PM Bryan Wooten <<a href="mailto:bryan.wooten@utah.edu">bryan.wooten@utah.edu</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div bgcolor="white" lang="EN-US">
<div class="gmail-m_-7792093114906003570WordSection1">
<p class="MsoNormal"><span style="font-size:11pt">Our IDP returns scoped eppn but our Grouper instance wants unscoped for our Grouper subjectID filter. (We had success with CAS for SSO)</span><br></p>
<p class="MsoNormal"><span style="font-size:11pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt">Is there a way to define unscoped eppn for any given SP? Either on the IDP side or SP side?</span></p></div></div></blockquote><div><br></div><div>ePPN is scoped by definition. The simplest answer is that you just need an unscoped attribute like uid. (I don't know how many folks federate their Grouper installations across authentication realms, so I'm not sure how far beyond the simple case one needs to worry.)</div><div><br></div><div>The Grouper wiki has some documentation: <a href="https://spaces.at.internet2.edu/display/Grouper/Authentication+to+the+Grouper+UI">https://spaces.at.internet2.edu/display/Grouper/Authentication+to+the+Grouper+UI</a></div><div><br></div><div>Greg</div></div></div>