IdP to allow only users within given IP range to access a SP

Stefano Zanmarchi zanmarchi at gmail.com
Fri Aug 23 08:13:32 EDT 2013


Thanks to all for your helpfulness and the thorough analisys!
We need to send just the user-mail attribute and will follow Jan's way (not
having activated the backend channel makes it quite straightforward). It's
OK for us if the SP gives a generic error.

It'd be very nice though if a future version of the IdP could do this out
of the box, maybe with a couple of new elements in the relying-party.xml
configuration file to indicate the "allowed IP range" and the customizable
"you're not allowed to authenticate" page.

Best,
Stefano



On Thu, Aug 22, 2013 at 4:03 PM, Manuel Haim <haim at hrz.uni-marburg.de>wrote:

> Hi Douglas,
>
> Am 22.08.2013 15:47, schrieb Douglas E. Engert:
> > Thanks, this might solve my problem.
> >
> http://shibboleth.1660669.n2.nabble.com/Restricting-Authentication-to-a-subset-of-Users-td6375260.html
> >
> >   Will have to take a look.
>
>
> you are welcome!
>
> -Manuel
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130823/fb693b2b/attachment.html 


More information about the users mailing list