Disallow eppn/affiliation to be asserted by the wrong IdP

Peter Schober peter.schober at univie.ac.at
Thu Oct 11 14:50:10 EDT 2012


* Cantor, Scott <cantor.2 at osu.edu> [2012-10-11 19:48]:
> <william.spooner at eaglegenomics.com> wrote:
> >The upshot; it's going to be too much effort to configure shibboleth to
> >handle this natively at the SP end. My solution is an apache
> >PerlAuthzHandler that uses the persistent-id to check that the userid is
> >from the correct IdP entity based on per-IdP regexps. Using a handler
> >means that the application layer remains unaware of IdP shenanigans. Bit
> >of a shame, but it's a case of "better the devil you know".
> 
> The SP does that for you as well. It checks the NameQualifier and
> SPNameQualifer in a persistent NameID against the asserting and relying
> party names.

AFAIU the intention was to check the values of /other/ attributes
based on the issuer of the assertion or persistent NameID.
-peter


More information about the users mailing list