May a shibboleth IdP deliver attributes for authZ without preceding authN ?

Chad La Joie lajoie at itumi.biz
Mon Oct 10 13:26:34 BST 2011


ooppsss...  that should say "No, out of the BOX the IdP..."

On Mon, Oct 10, 2011 at 08:26, Chad La Joie <lajoie at itumi.biz> wrote:
> No, out of the IdP does not require that the user have an active
> session in order to answer an attribute query about that user.  A
> deployer *could* create a filter policy that makes such a requirement
> but I've not heard of anyone doing so.
>
> The only requirement, from the IdP side, is that subject name
> identifier given in the attribute query must be something that is
> usable for looking up information about the user (e.g., a username or
> email address).
>
> On Mon, Oct 10, 2011 at 08:14, Markus Ludwig Grandpre
> <markus.grandpre at uni-konstanz.de> wrote:
>> Is there a SAML confirm approach to make Shibboleth only to deliver
>> required attribute values for authZ after authN has taken place
>> somewhere else?
>
> --
> Chad La Joie
> www.itumi.biz
> trusted identities, delivered
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list