Franchise access being authenticated by our Shibboleth IdP
Keith Carr
kecarr at sgul.ac.uk
Thu Feb 23 16:46:47 GMT 2012
On 23/02/12, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> > I'm not sure what you mean here, can you explain further in layman's terms?
>
> Affiliations are not about services, they're only about users. A student is a student because he's a student, not because a service is saying "if you want to get access, tell me you're a student". It's a fact of identity that should be storable in a directory or database and then expressed uniformly to all services.
>
> Using them for authorization is tricky, and arguably a bad idea in many cases. Misusing them by telling IdPs to "assert an affiliation regardless of its truth as a substitute for an entitlement" is also a bad idea, and that one creates problems for IdPs that already support affiliation in the manner intended.
>
> In fact, the recent thread on MACE-Dir about this exact issue led one person to send a somewhat hyperbolic, probably not entirely serious, diatribe about that exact point. "Don't use them, because then people will start having to lie about affiliation in order to get people access to things".
>
> The other comments in the thread were in the same vein as my point. If you rely on this sort of attribute for authorization, then the exceptions bite you in the butt later because it's *not* really students that get access it's "the set of people that get access" that get access. At a minimum, you end up having to combine affiliation with something else anyway.
>
Thanks for that Scott - I understand now and has cleared up in my head what you're all pointing towards.
I've just sent replies to Chad and Peter with this in mind; so providing entitlement is preferable and I completely understand that now. It should be do-able I just need to understand how I can differentiate a standard user to franchise user considering their list of resources available may overlap in some areas somewhat.
Thanks for the explanation,
-Keith
>
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120223/320c4556/attachment.html
More information about the users
mailing list