WebAuthn: Issue with Fido metadata?

Mats Luspa mats.luspa at irf.se
Tue Oct 29 19:43:11 UTC 2024


Hello!

I think it has to do with that irfAuthorizedService is a multi-value 
attribute.

When I used uid, that is a single-value attribute it worked.

I use ldap.

/Regards Mats

Den 2024-10-29 kl. 16:45, skrev Philip Smart:
>
>
>> On 29 Oct 2024, at 15:32, Mats Luspa via dev <dev at shibboleth.net> wrote:
>>
>> Thanks, that suggestion sounds good.
>>
>> We have an attribute called irfAuthorizedService which is an 
>> multi-valued attribute that contains all the services that a user has 
>> access to.
>> I was going to test the suggestion with the following configuration:
>>
>> <entry key="AccessByAttribute">
>>             <bean parent="shibboleth.PredicateAccessControl">
>>                 <constructor-arg>
>>                     <bean parent="shibboleth.Conditions.SimpleAttribute">
>>                         <property name="attributeValueMap">
>>                             <map>
>>                                <entry key="irfAuthorizedService">
>>                                     <list>
>> <value>shibAdmin</value>
>>                                     </list>
>>                                </entry>
>>                             </map>
>>                         </property>
>>                     </bean>
>>                 </constructor-arg>
>>             </bean>
>> </entry>
>>
>> I webauthn.properties file I have:
>>
>> idp.authn.webauthn.admin.management.accessPolicy = AccessByAttribute
>>
>> I have used irfAuthorizedService in other services as to said.
>>
>> But it seems not to work with this attribute ("You do not have access 
>> to the requested resource."). I suppose there is more configuration I 
>> must make?
>>
>
> There shouldn't be. Is there anything in the logs about what 
> attributes are being resolved, what access policy is being used, and 
> what attributes are being checked (e.g. `Checking for attribute:` in 
> the log)?
>
>> /Regards Mats
>>
>> On 2024-10-29 15:57, Philip Smart via dev wrote:
>>> Thanks, Micheal.
>>>
>>> The admin flow should be resolving attributes by default, even if 
>>> the properties file says it is not. That is a typo; I will commit a 
>>> fix for that now.
>>>
>>> Phil
>>>
>>>> On 29 Oct 2024, at 14:46, Michael Grady <mgrady at unicon.net> wrote:
>>>>
>>>>
>>>> 	
>>>> You don't often get email from mgrady at unicon.net. Learn why this is 
>>>> important <https://aka.ms/LearnAboutSenderIdentification>
>>>> 	
>>>>
>>>>
>>>>
>>>>> On Oct 29, 2024, at 9:31 AM, Philip Smart via dev 
>>>>> <dev at shibboleth.net> wrote:
>>>>>
>>>>> Yup, as Scott said, this is all highly configurable based on the 
>>>>> usual IdP access control mechanisms. From a plugin perspective, if 
>>>>> you did want to change the policy, you can by using the property 
>>>>> (once you have defined the new policy):
>>>>>
>>>>> idp.authn.webauthn.admin.management.accessPolicy = <SomePolicy>
>>>>
>>>> An example for other admin endpoints is the following in 
>>>> admin/admin.properties:
>>>>
>>>> #idp.resolvertest.logging = ResolverTest
>>>> idp.resolvertest.accessPolicy = ResolverAccessByAttribute
>>>> idp.resolvertest.authenticated = true
>>>> #idp.resolvertest.nonBrowserSupported = false
>>>> idp.resolvertest.defaultAuthenticationMethods = 
>>>> saml2/https://refeds.org/profile/mfa
>>>> idp.resolvertest.resolveAttributes = true
>>>> #idp.resolvertest.postAuthenticationFlows =
>>>>
>>>> #idp.mdquery.logging = MetadataQuery
>>>> idp.mdquery.accessPolicy = ResolverAccessByAttribute
>>>> idp.mdquery.authenticated = true
>>>> #idp.mdquery.nonBrowserSupported = false
>>>> idp.mdquery.defaultAuthenticationMethods = 
>>>> saml2/urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
>>>> idp.mdquery.resolveAttributes = true
>>>> #idp.mdquery.postAuthenticationFlows =
>>>>
>>>> and then something like this added into the 
>>>> shibboleth.AccessControlPolicies map in access-control.xml:
>>>>
>>>>         <entry key="ResolverAccessByAttribute">
>>>>             <bean parent="shibboleth.PredicateAccessControl">
>>>> <constructor-arg>
>>>>                     <bean 
>>>> parent="shibboleth.Conditions.SimpleAttribute">
>>>>                         <property name="attributeValueMap">
>>>> <map>
>>>>  <entry key="activeDirectoryMemberOfShort">
>>>> <list>
>>>> <value>IDM--access-resolver</value>
>>>> </list>
>>>>  </entry>
>>>> </map>
>>>> </property>
>>>>                     </bean>
>>>> </constructor-arg>
>>>>             </bean>
>>>>         </entry>
>>>>
>>>> where you are saying a particular resolved attribute needs to have 
>>>> a particular value in order to have access.
>>>>
>>>> --
>>>> Michael A. Grady
>>>> IAM Architect, Unicon, Inc.
>>>>
>>>>
>>>>
>>>
>>>
>>> Jisc is a registered charity (number 1149740) and a company limited 
>>> by guarantee which is registered in England under company number. 
>>> 05747339, VAT number GB 197 0632 86. Jisc’s registered office is: 4 
>>> Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
>>>
>>> Jisc Services Limited is a wholly owned Jisc subsidiary and a 
>>> company limited by guarantee which is registered in England under 
>>> company number 02881024, VAT number GB 197 0632 86. The registered 
>>> office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
>>>
>>> Jisc Commercial Limited is a wholly owned Jisc subsidiary and a 
>>> company limited by shares which is registered in England under 
>>> company number 09316933, VAT number GB 197 0632 86. The registered 
>>> office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
>>>
>>> For more details on how Jisc handles your data see our privacy 
>>> notice here: https://www.jisc.ac.uk/website/privacy-notice
>>>
>>>
>> -- 
>> --
>> Mats Luspa
>> Phone: +46 (0)980 79 022
>> Cellular phone: +46 (0)725813330
>> Institutet för rymdfysik               Fax: +46 (0)980 79 050
>> Swedish Institute of Space Physics      email:matsl at irf.se
>> Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
>> Postal address: Box 812, SE-981 28 Kiruna
>> --
>> PGP Public Key:https://www.irf.se/pgp/matsl
>> Digital vcard:https://www.irf.se/vcard/mats.luspa
>> -- 
>> To unsubscribe from this list send an email to 
>> dev-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20241029/fdd67bc8/attachment-0001.htm>


More information about the dev mailing list