Decrypting attributes on-the-fly
Griffin Cheng [CLIB]
cscheng at cpce-polyu.edu.hk
Thu Feb 6 20:40:05 EST 2014
Dear Mr. Cantor,
Further thoughts: Do you mean I can actually encrypt the data, stored in an attribute of the IdP (which is an ADFS btw), and decrypt it using the key pair during Shibboleth installation? All I need is to tell Shibboleth to decrypt that attribute automatically, when authentication is successful, right?
Regards,
Griffin CHENG.
Telephone: 3746 0853
From: Griffin Cheng [CLIB]
Sent: Friday, 07 February, 2014 09:19
To: 'dev at shibboleth.net'
Subject: Re: Decrypting attributes on-the-fly
Dear Mr. Cantor,
Sorry, I am a newbie to Shibboleth. I do not understand what "plugin hook" is about and how the whole workflow can "attach" to it. The problem is, the attribute in question is stored encrypted in the first place, using key that is not part of the Shibboleth itself. Thank you.
Regards,
Griffin CHENG.
-----
On 2/6/14, 7:23 PM, "Griffin Cheng [CLIB]" <cscheng at cpce-polyu.edu.hk<mailto:cscheng at cpce-polyu.edu.hk>>
wrote:
>The question is: how can I decrypt this attribute on-the-fly, without
>changing the requesting application, which is a black box. I think I
>may be able to something during the attribute mapping but I have no
>clue for now.
Both the SP and the IdP have plugin hooks enabling this, but you'd have to write code, there really isn't anything else you can do.
-- Scott
-----
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20140207/3dd2cdfb/attachment.html
More information about the dev
mailing list