Page tree

The Shibboleth 2.x software has reached its End of Life and is no longer supported. This documentation is available for historical purposes only. See the IDP4 and SP3 wiki spaces for current documentation on the supported versions.

Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

Attribute Issuer Entity Attribute Regular Expression Matching Rule

This matching rules evaluates to true if the attribute issuer's metadata contains an Entity Attribute that has a value that matches a given regular expression.

This filter requires that the metadata for the attribute issuer is loaded and available.
This filter only operates on Attribute elements within the EntityAttributes, it does not use any Assertion elements.

Define the Rule

This rule is defined by the element <PolicyRequirementRule xsi:type="saml:AttributeIssuerEntityAttributeRegexMatch">, for policy requirements rules, and <PermitValueRule xsi:type="saml:AttributeIssuerEntityAttributeRegexMatch">, for permit value rules, with the following required attributes:

  • attributeName - the name of the entity attribute
  • attributeValueRegex - the regular expression an entity attribute value must match

This rule also supports the following optional attribute:

  • attributeNameFormat - the name format the entity attribute must have; otherwise any format is accepted
Example Policy Requirement Rule using the AttributeIssuerEntityAttributeRegexMatch Function
<PolicyRequirementRule xsi:type="saml:AttributeIssuerEntityAttributeRegexMatch" 
                       attributeValueRegex="\urn\\:policy\:ABCD.*" />
  • No labels