Question on Login Handlers
Cantor, Scott
cantor.2 at osu.edu
Thu Aug 22 17:25:41 EDT 2013
On 8/22/13 4:33 PM, "Kevin P. Foote" <kpfoote at iup.edu> wrote:
>
>I think Chris is right on the front side.. your LDAP2 specific app could
>request a special handler. But, the PreviousSession handler is where
>things run into issues and your LDAP2 group will have access to stuff
>they should not.
The handler won't run if you're using specific AuthnContext classes in the
request from the special apps.
You can't do any of this properly unless you configure the SPs, and in
that case, you should simply be using attributes.
The OP is in for a world of pain here and should simply tell them he'll
supply attributes as needed to drive policy and require appropriate
policy. This is authn == authz. It seems to be like smallpox; seemingly
eradicated but now coming back due to a rise in new security staff coming
from apparently questionably competent backgrounds.
-- Scott
More information about the users
mailing list