IdP to allow only users within given IP range to access a SP
Stefano Zanmarchi
zanmarchi at gmail.com
Wed Aug 21 23:51:46 EDT 2013
Thank you for the hint Ian, but IdPAuthIP is not the solution because the
SP expects to receive attributes so username/password authentication is a
must. Firewalling is not an option because other SPs dont have this IP
restriction.
We need - prior to authentication - a check done by the IdP on browser IP
and SP being accessed.
Any help here would be greatly appreciated.
Stefano
Il giorno 21/ago/2013 23:56, "Ian Rifkin" <irifkin at brandeis.edu> ha
scritto:
> Hi Stefano,
>
> we need to limit access to a given SP to users within a given IP range.
>> We can only work on the IdP side.
>>
>
> I'm not an expert, so maybe someone else can chime in, but I think it
> would depend on your configuration. You can put IP restrictions in
> webserver and firewall software, but you can't do that if you use the IdP
> for other SPs that don't have this IP restriction. If you have a custom
> auth piece it looks like you can read about
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthIP. Or
> perhaps attempt something more fancy/custom.
>
> Taking a step back, how do you currently do authentication? And what does
> the SP expect to receive back from you (do they do any authorization or
> does the SP just assume if they get a reply they are good?).
>
> Regards,
> Ian
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130822/c0c8a7b9/attachment.html
More information about the users
mailing list