Can you try this patch ? You will need to build upstream/master.
I've added an new attribute called "EntityID" to the PicketLinkSP configuration element. If specified, PicketLink will also consider the value of this attribute when validating audiences.
|