<div dir="ltr">Robert - <div><br></div><div><div> I have seen this when I had multiple internal attribute resolver IDs defining EPPN. (In my case it was different values as I worked to transition from a legacy "bad" EPPN value to a proper stable one.)</div><div><br></div><div> If both releases are working with the same attribute resolver attribute ID, it's possible that you've had this issue in other places, but the Cirrus Proxy is (correctly) interpreting things in ways most of your SPs don't bother to do.<br><div><br></div><div> Assuming the included <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199511404/AACLI">aacli utility</a> is usable in your environment, does it display the attribute twice (when you use the --saml2 option)?</div><div><br></div><div> If so (and this is the same single attribute ID, this recent thread may be of use -- <a href="https://shibboleth.net/pipermail/users/2024-October/055718.html">https://shibboleth.net/pipermail/users/2024-October/055718.html</a></div><div><br></div><div>Steve.</div></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Nov 7, 2024 at 5:28 PM Cantor, Scott via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">If you're asking about the IdP and its filtering rules, you don't end up asserting the same value twice because two different rules permit a value.<br>
<br>
Additionally, the IdP de-dups coming out of the resolver to begin with.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>