Franchise access being authenticated by our Shibboleth IdP
Keith Carr
kecarr at sgul.ac.uk
Thu Feb 23 01:34:07 GMT 2012
On 22/02/12, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> > A Query would be performed on the database using a data connector for the
> > requesting resource and values returned for all the franchises. Each
> > franchise "field" returned from the query would be put into an attribute
> > (FRANA_GRANTED and FRANB_GRANTED). This would then be assessed
> > along with the "shibbolethset" attribute to determine whether the user
> > should be given a eduPersonAffiliation attribute value which will grant access
> > to the resource.
>
> That's a fundamental problem. Affiliation is not based on whether you have access to a resource, it's a fact of the identity involved independent of any resource. It's a very bad idea to conflate that.
>
> -- Scott
>
Hi Scott,
I agree, however I'm failing to see another way to accomplish the task I have been set.
In an ideal world I'm guessing that I would set some values for eduPersonEntitlement indicating whether the user was allowed acces to the resource and agree these with the SP's?
The problem I can see in this is getting all the SP's to organise and agree these within the time-frame.
Is there another way in which I should be attacking this?
- Keith
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120223/f3c8fa36/attachment-0001.html
More information about the users
mailing list