Question on Login Handlers

Brewer, Edward L lee.brewer at Vanderbilt.Edu
Thu Aug 22 18:52:43 EDT 2013


David,

The case that is cited that is considered the "scariest" is the following.

User A is in both LDAP1 and LDAP2... the data is the same.
User A is terminated.... Login access to LDAP1 is disabled...  user's information is still there.

User A logins into an application and is able to auth to LDAP2 and gain access... plus since they are in LDAP1 their attributes will be there to pass on to the app

So I at least need a way of not sending the attribute information from LDAP1.


Thanks,
Lee




>Ok... Now I understand better what Scott was saying.. authentication == authorization...   Maybe I am a little obtuse...

>Well, actually we have not had a policy of authentication is equivalent to authorization.  Many of our SPs have some level of access control that is >driven by attribute information or other data.  It looks I just need to review each SP to ensure that is true.  There is a lot of people worried about an >inadvertent access to an application... So, maybe just having JAAS configured with both without creating a new login handler is adequate

>>Yeah, I get that too -- concern about inadvertent access.  I use that to take the opportunity to ask them about the specific apps they're concerned >>about & also educate them about our account lifecycle.  Generally, once I mention that we never lock or close a credential until we're notified of >>the death of the holder, the conversation quickly moves from generic unspecific concerns to a more productive conversation on how they can >>leverage the IAM infrastructure to automatically grant/revoke access to apps they're concerned about.

Dave

--
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130822/74b1d276/attachment.html 


More information about the users mailing list