<div dir="ltr">(1) what Scott wrote<div><br></div><div>(2) bang head on table</div><div><br></div><div>(3) gin up a single valued attribute and encode and release as "mail" to the many SPs that break when encountering multi-values of multi-valued attribute.  You can do something really crude like pick the "first" value of the mail attribute, or your institution or email admins may have a canonical email address assigned for all users that you can retrieve from your attribute store.</div><div><br></div><div>(4) bang head on table</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, May 26, 2020 at 9:44 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Are you the IdP or the SP?<br>
<br>
As an IdP you can do many different things, up to and including per-value consent (but which a user will probably not understand your intent/purpose since they don't *care* about your email problem caused by Amazon's bug).<br>
<br>
As an SP, you cannot use a standard attribute like "mail" that is defined to be multiply-valued, and expect every IdP in the world to be willing to impose your preferred limitation on the syntax, even though most actual practice around it is for a single value.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>