May a shibboleth IdP deliver attributes for authZ without preceding authN ?
Chad La Joie
lajoie at itumi.biz
Mon Oct 10 13:26:02 BST 2011
No, out of the IdP does not require that the user have an active
session in order to answer an attribute query about that user. A
deployer *could* create a filter policy that makes such a requirement
but I've not heard of anyone doing so.
The only requirement, from the IdP side, is that subject name
identifier given in the attribute query must be something that is
usable for looking up information about the user (e.g., a username or
email address).
On Mon, Oct 10, 2011 at 08:14, Markus Ludwig Grandpre
<markus.grandpre at uni-konstanz.de> wrote:
> Is there a SAML confirm approach to make Shibboleth only to deliver
> required attribute values for authZ after authN has taken place
> somewhere else?
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list