<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
Thanks for you quick reply Scott <span id="🙂">🙂</span></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
No, unfortunately I do not control any of the IdP:s. This one require an AttributeConsumingService, none of the others do. <span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">They,
the external IdP, use it to know which backend system they need to contact to be able to put together the attributes in the response. They have a lot of backend systems they need to contact and want to keep that to a minimum.</span></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
So I guess my option would be:</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<ol data-editing-info="{"orderedStyleType":3,"unorderedStyleType":1}" data-listchain="__List_Chain_165">
<li style="list-style-type: "1) ";">Add an AttributeConsumingService in my proxys SP-metadata as default and have it contain the sum of all attributes from all IdP:s and set them as not required. Then I only get one SP-metadata for the proxy.</li><li style="list-style-type: "2) ";"><span>Make a specific SP-metadata for just that IdP, meaning I need to manage two different sets for the same SP.</span></li><li style="list-style-type: "3) ";"><span>Go to IdP5</span></li></ol>
<div><span>I am starting to think number 2 would be the cleaner one.</span></div>
<div><span><br>
</span></div>
<div><span>Cheers,</span></div>
<div><span><br>
Tomas</span></div>
<div><span><br>
</span></div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Wednesday, November 1, 2023 17:30<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> tomas.stenlund@telia.com <tomas.stenlund@telia.com><br>
<b>Subject:</b> Re: Setting AttributeConsumingIndex in IdP 4</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">There is no practical means of doing this in 4, just some very advanced low level ways.<br>
<br>
I would rethink your approach altogether unless you control all the IdPs because nothing but Shibboleth supports that mechanism to begin with, and there are few if any deployers of Shibboleth that would honor it. It acts as a filtering mechanism by default,
but it won't cause attributes to be produced or released, and the lack of booleans in the articulation of requirements makes it largely worthless in practice.<br>
<br>
-- Scott<br>
<br>
<br>
</div>
</span></font></div>
</body>
</html>