<div dir="ltr"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div><div>Hi -</div></div><div><br></div><div>We are using the proxied IDP function of IDP4 with great success !</div><div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+to+another+IdP</a><br></div><div><br></div><div>Is it possible to authenticate (or grant/deny access) by affiliation?  (The proxied IDP is supplying attributes, including affiliation, which are processed in the attribute-filter.xml)</div><div><br></div><div>- Jerry</div></div></div></div></div></div></div></div></div></div></div></div>