We are attempting to transition from LDAP authentication to Shibboleth
authentication and are having an issue in regards to shib groups. Our current
configuration uses the "ismemberof" ldap attribute to build the user groups
used for privilege assignment. Now that we have setup Shib authentication, we
are being presented with groups created off of the shib "affiliation" attribute
rather than the shib "entitlement" attribute that represents our "ismemberof"
of LDAP. Is there any way to use our shib "entitlement" attribute to build
Old Dominion University