In V3.2.0 the need for multiple namespaces was removed. With the exception of deprecated Matchers and Policy Rules, everything can now be expressed by the urn:mace:shibboleth:2.0:afp
schema. Many of the Matchers and Policy Rules preserve the same body (so xsi:type="basic:AND"
becomes xsi:type="AND"
), but some have been abbreviated.
The following table shows the appropriate mapping. See AttributeFilterPolicyConfiguration for the documentation
Legacy Type | Current Type | Notes |
---|---|---|
basic:AND | AND | |
basic:ANY | ANY | |
basic:AttributeIssuerRegex | Deprecated function. The legacy type is still supported in V3, but will cause a warning to be issued. | |
basic:AttributeIssuerString | Deprecated function. The legacy type is still supported in V3, but will cause a warning to be issued. | |
basic:AttributeRequesterRegex | RequesterRegex | |
basic:AttributeRequesterString | Requester | |
basic:AttributeScopeRegex | ScopeRegex | |
basic:AttributeScopeString | Scope | |
basic:AttributeValueRegex | ValueRegex | |
basic:AttributeValueString | Value | |
basic:AuthenticationMethodRegex | AuthenticationMethodRegex |
|
basic:AuthenticationMethodString | AuthenticationMethod | |
basic:NOT | NOT | |
basic:NumberOfAttributeValues | NumberOfAttributeValues | |
basic:OR | OR | |
basic:Predicate | Predicate | |
basic:PrincipalNameRegex | PrincipalNameRegex | |
basic:PrincipalNameString | PrincipalName | |
basic:Rule | Rule | |
basic:Script | Script | |
saml:AttributeInMetadata | AttributeInMetadata | |
saml:AttributeIssuerEntityAttributeExactMatch | Never supported in V3. Error issued | |
saml:AttributeIssuerEntityAttributeRegexMatch | Never supported in V3. Error issued | |
saml:AttributeIssuerInEntityGroup | Never supported in V3. Error issued | |
saml:AttributeIssuerNameIDFormatExactMatch | Never supported in V3. Error issued | |
saml:AttributeRequesterEntityAttributeExactMatch saml:EntityAttributeExactMatch | EntityAttributeExactMatch | AttributeRequesterXYZ types were V2 only and are supported but warn in V3 |
saml:AttributeRequesterEntityAttributeRegexMatch saml:EntityAttributeRegexMatch | EntityAttributeRegexMatch | Never supported in V3. Error issued |
saml:AttributeRequesterInEntityGroup saml:InEntityGroup | InEntityGroup | Never supported in V3. Error issued |
| NameIDFormatExactMatch | Never supported in V3. Error issued |
saml:MappedAttributeInMetadata | MappedAttributeInMetadata | |
saml:RegistrationAuthority | RegistrationAuthority |