<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><br class=""><div><br class=""><blockquote type="cite" class=""><div class="">On Jun 3, 2022, at 7:26 AM, Cantor, Scott via users <<a href="mailto:users@shibboleth.net" class="">users@shibboleth.net</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><blockquote type="cite" style="font-family: Helvetica; font-size: 18px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;" class=""> It seems the group in CAS service definition of CASServiceRegistry cannot be used in InEntityGroup type of<br class="">policy rule in AttributeFilterConfiguration. I can’t group related CAS services definition in this way to have the<br class="">same attribute release policy. Is it not implemented or a bug?</blockquote></div></blockquote></div><div class=""><br class=""></div>And what causes you to think the above? We've used the<div class=""><br class=""></div><div class=""> <PolicyRequirementRule xsi:type="InEntityGroup" groupID="CAS_groupname_from_registry" /></div><div class=""><br class=""></div><div class="">quite a bit in the attribute-filter file, and if it has stopped working, there sure haven't been any reports of such. </div><div class=""><br class=""><div class="">
<div>--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.</div><div class=""><br class=""></div><br class="Apple-interchange-newline">
</div>
<br class=""></div></body></html>