IdP to allow only users within given IP range to access a SP
Douglas E. Engert
deengert at anl.gov
Thu Aug 22 09:47:33 EDT 2013
On 8/22/2013 8:20 AM, Manuel Haim wrote:
>
> 2) If the above is no option, you must write an IdP plugin which blocks
> the IdP's attribute forwarding based on the user's IP address (or other
> attribute values). We use a customized copy of the uApprove filter
> (ch.SWITCH.aai.uApprove.Intercepter) to accomplish this, i.e. users
> lacking the
> eduPersonEntitlement=urn:mace:dir:entitlement:common-lib-terms attribute
> value are blocked and shown a no-access page.
> I have just uploaded the jar file and the sources here if you want to
> have a look:
> http://www.staff.uni-marburg.de/~haimm/unimr-spaccessfilter.shib2.uapprove240.2013_08_22.zip
>
Thanks, this might solve my problem.
http://shibboleth.1660669.n2.nabble.com/Restricting-Authentication-to-a-subset-of-Users-td6375260.html
Will have to take a look.
>
> -Manuel
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
--
Douglas E. Engert <DEEngert at anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
More information about the users
mailing list