<div dir="ltr"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div>Hello,</div><div><br></div><div>I would like to configure our Shibboleth SP (v3.0.4 currently) to extract all attributes from an assertion including those which we don't explicitly map. The use case is that some identity providers release nonstandard attributes and mapping each one on our production SP causes delays in customer onboardings.</div><div><br></div><div>I wasn't able to find an answer in the SPv3 documentation or by searching mailing list archives or the web. I'm considering an external program to monitor the shibd logs and automatically create new mappings when <span style="color:rgb(0,0,0);white-space:pre-wrap">"skipping unmapped SAML 2.0 Attribute" is logged. My intent would be to use the attribute name & nameformat from the assertion to make an identifier for each of these.</span></div><div><span style="color:rgb(0,0,0);white-space:pre-wrap"><br></span></div><div><span style="color:rgb(0,0,0);white-space:pre-wrap">Is there a way to do this using SP configuration rather than writing something to react to log entries?</span></div><div><span style="color:rgb(0,0,0);white-space:pre-wrap"><br></span></div><div><span style="color:rgb(0,0,0);white-space:pre-wrap">Thanks in advance,</span></div><div><span style="color:rgb(0,0,0);white-space:pre-wrap">-jesse</span></div></div></div></div></div></div></div>