using Shib-Identity-Provider in XML Access Control

Vladimir Mencl vladimir.mencl at canterbury.ac.nz
Thu Aug 1 18:23:39 EDT 2013


Hi,

I'm trying to configure access control to my SP with an external XML 
Access Control file - and in the rules, I'd like to refer to attributes 
(working all fine) and the IdP entityID (restrict access based on the 
IdP the user came from).

The description for the require clause of a Rule element in the XML 
access control file says it can be one of the predefined values 
(valid-user, user, authContext{Class/Decl}Ref) OR "ID/alias of an 
attribute".

Is there a way to refer to the other "pseudo" attributes kept about a 
session - or in particular, the IdP entityID?

I tried using "Shib-Identity-Provider" (how the IdP entityID appears in 
the Apache Environment), but was getting log messages:

> [Mon Jul 29 16:49:44 2013] [warn] [client 132.181.65.178] rule requires attribute (Shib-Identity-Provider), not found in session

Is there a way to refer to the IdP entityID from the Access Control rules?

Any advice would be highly appreciated.

Many thanks in advance.


Cheers,
Vlad

-- 
Vladimir Mencl, Ph.D.
E-Research Services and Systems Consultant
BlueFern Computing Services
University of Canterbury
Private Bag 4800
Christchurch 8140
New Zealand

http://www.bluefern.canterbury.ac.nz
mailto:vladimir.mencl at canterbury.ac.nz
Phone: +64 3 364 3012
Mobile: +64 21 997 352
Fax: +64 3 364 3002


More information about the users mailing list