IdP to allow only users within given IP range to access a SP

Douglas E. Engert deengert at anl.gov
Thu Aug 22 09:47:33 EDT 2013


On 8/22/2013 8:20 AM, Manuel Haim wrote:

>
> 2) If the above is no option, you must write an IdP plugin which blocks
> the IdP's attribute forwarding based on the user's IP address (or other
> attribute values). We use a customized copy of the uApprove filter
> (ch.SWITCH.aai.uApprove.Intercepter) to accomplish this, i.e. users
> lacking the
> eduPersonEntitlement=urn:mace:dir:entitlement:common-lib-terms attribute
> value are blocked and shown a no-access page.
> I have just uploaded the jar file and the sources here if you want to
> have a look:
> http://www.staff.uni-marburg.de/~haimm/unimr-spaccessfilter.shib2.uapprove240.2013_08_22.zip
>

Thanks, this might solve my problem.
  http://shibboleth.1660669.n2.nabble.com/Restricting-Authentication-to-a-subset-of-Users-td6375260.html

  Will have to take a look.

>
> -Manuel
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>

-- 

  Douglas E. Engert  <DEEngert at anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444


More information about the users mailing list