<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">Hello,</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I'm attempting to federate with a broken SP that isn't seeing the correct client source for the the Address attribute in SubjectConfirmationData.  Watching the assertion, Address is set correctly, but their logs say it's a mismatch.  I'm thinking their ACS
 is located behind a load-balancer / reverse proxy that's changing the client's source IP.  They claim the other IDPs they've federated with don't populate Address.<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Is there a way within Shibboleth to prevent Address from being added to the SubjectConfirmationData?  My searches of the wiki haven't turned anything up, except the checkAddress RP profile config (<a href="https://wiki.shibboleth.net/confluence/display/IDP4/SAML2SSOConfiguration#55804373d9264505e7b248218c3ea26c3fd35a11" target="_blank" rel="noopener noreferrer" data-auth="NotApplicable">https://wiki.shibboleth.net/confluence/display/IDP4/SAML2SSOConfiguration#55804373d9264505e7b248218c3ea26c3fd35a11</a>). 
 However, this appears to be for messages coming into the IDP, not leaving.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
I get that this is in place to prevent someone from hijacking your assertion and SP session, but I need to investigate whether this can be done regardless.<br>
</div>
<div class="x__Entity x__EType_OWALinkPreview x__EId_OWALinkPreview x__EReadonly_1">
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Thanks,<br>
</div>
<font size="2"><span style="font-size:12pt">Tony Plovich</span><span style="font-size:11pt"></span></font><br>
<font size="2"><span style="font-size:11pt"></span></font></div>
<div>
<div id="Signature">
<div>
<div id="divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top:0px; margin-bottom:0px; margin-top:0; margin-bottom:0"><font size="2"><span style="font-size:11pt"></span><span style="font-size:12pt">Business Information Systems</span><span style="font-size:11pt"><br>
</span><span style="font-size:12pt">Argonne National Laboratory</span><span style="font-size:11pt"><br>
</span></font><br>
</p>
</div>
</div>
</div>
</div>
</body>
</html>