<div dir="ltr">Hey All,<div><br></div><div>We're running Shibboleth IdP 4.0.1 and have an attribute filter to release a set of core attributes to InCommon members:</div><div><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div><!-- Attribute release for all InCommon SPs --></div><div><AttributeFilterPolicy id="releaseToInCommon">      </div><div>    <PolicyRequirementRule xsi:type="EntityAttributeExactMatch"</div><div>                    attributeName="<a href="http://macedir.org/entity-category">http://macedir.org/entity-category</a>"</div><div>                    attributeValue="<a href="http://id.incommon.org/category/registered-by-incommon">http://id.incommon.org/category/registered-by-incommon</a>"/></div><div>    <AttributeRule attributeID="eduPersonPrincipalName"></div><div>        <PermitValueRule xsi:type="ANY" /></div><div>    </AttributeRule></div><div>    <AttributeRule attributeID="eduPersonScopedAffiliation"></div><div>        <PermitValueRule xsi:type="ANY" /></div><div>    </AttributeRule></div><div>    <AttributeRule attributeID="givenName"></div><div>        <PermitValueRule xsi:type="ANY" /></div><div>    </AttributeRule></div><div>    <AttributeRule attributeID="surname"></div><div>        <PermitValueRule xsi:type="ANY" /></div><div>    </AttributeRule></div><div>    <AttributeRule attributeID="displayName"></div><div>        <PermitValueRule xsi:type="ANY" /></div><div>    </AttributeRule></div><div>    <AttributeRule attributeID="email"></div><div>        <PermitValueRule xsi:type="ANY" /></div><div>    </AttributeRule></div><div></AttributeFilterPolicy></div></blockquote><div><br></div><div>There's a particular InCommon SP for which we have to omit sending the eduPersonScopedAffiliation attribute and I haven't been able to figure out how to do that. Does anyone have an idea of how to achieve this?</div><div><br></div><div>Thanks,</div><div>Jason</div><div><br></div><div><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72"><b>VERIFY before you click!!</b>
  - Attackers make their emails look like they come from someone they don't.
  - Attackers make links look like they go to websites they don't.
  - Attackers disguise malware as receipts, invoices, faxes, etc.</pre><pre cols="72">Forward suspicious emails to <a href="mailto:phishing@swarthmore.edu" style="font-family:Arial,Helvetica,sans-serif" target="_blank">phishing@swarthmore.edu</a><span style="font-family:Arial,Helvetica,sans-serif">.</span></pre></div></div></div></div></div></div></div></div></div></div></div></div></div></div>