using Shib-Identity-Provider in XML Access Control
Vladimir Mencl
vladimir.mencl at canterbury.ac.nz
Thu Aug 1 18:23:39 EDT 2013
Hi,
I'm trying to configure access control to my SP with an external XML
Access Control file - and in the rules, I'd like to refer to attributes
(working all fine) and the IdP entityID (restrict access based on the
IdP the user came from).
The description for the require clause of a Rule element in the XML
access control file says it can be one of the predefined values
(valid-user, user, authContext{Class/Decl}Ref) OR "ID/alias of an
attribute".
Is there a way to refer to the other "pseudo" attributes kept about a
session - or in particular, the IdP entityID?
I tried using "Shib-Identity-Provider" (how the IdP entityID appears in
the Apache Environment), but was getting log messages:
> [Mon Jul 29 16:49:44 2013] [warn] [client 132.181.65.178] rule requires attribute (Shib-Identity-Provider), not found in session
Is there a way to refer to the IdP entityID from the Access Control rules?
Any advice would be highly appreciated.
Many thanks in advance.
Cheers,
Vlad
--
Vladimir Mencl, Ph.D.
E-Research Services and Systems Consultant
BlueFern Computing Services
University of Canterbury
Private Bag 4800
Christchurch 8140
New Zealand
http://www.bluefern.canterbury.ac.nz
mailto:vladimir.mencl at canterbury.ac.nz
Phone: +64 3 364 3012
Mobile: +64 21 997 352
Fax: +64 3 364 3002
More information about the users
mailing list