limiting which IdPs can access an SP
Liam Hoekenga
liamr at umich.edu
Wed Jul 3 16:13:08 EDT 2013
We have a service provider that is using federation metadata in it's
MetadataProvider definition. As a result, we can craft login urls for any
IdP included in the metadata used by that SP, and it will let those users
in.
I know we could use the RequestMap to deny access based on attribute
values.
Short of ditching the federation metadata, and configuring
MetadataProviders for the specific IdPs we want to talk to, is there a way
to limit which IdPs it will permit authentication from? Can will filter
out the unwanted IdPs somehow?
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130703/6ac4def6/attachment.html
More information about the users
mailing list