forcing one protected area to only accept a specific IDP with other areas use many IDPs
Cantor, Scott
cantor.2 at osu.edu
Fri Feb 17 23:41:20 GMT 2012
>Is it possible to have an apache Requires directive that looks at the
>entityID of the authenticating IDP?
No, because we avoided giving people this tool, believing it would do more
harm than good. As of 2.5, the ability to extract Issuer into any
attribute you want means that the capability will be possible regardless
of our intent or opinion. By making it an indirect feature, it at least
requires some degree of understanding and thought to enable.
> I see that it exposes it to the app in Shib-Identity-Provider, but I
>don't see any way of getting at that in Apache. I can see that you can
>get to authnContextClassRef and authnContextDeclRef, but no equivalent
>for entityID. That would also seem to satisfy the requirement, if it's
>possible. If that's not possible, it seems like a logical feature
>request.
We believe it's not the right knob to use.
-- Scott
More information about the users
mailing list