limiting which IdPs can access an SP

Liam Hoekenga liamr at umich.edu
Wed Jul 3 16:13:08 EDT 2013


We have a service provider that is using federation metadata in it's
MetadataProvider definition.  As a result, we can craft login urls for any
IdP included in the metadata used by that SP, and it will let those users
in.

I know we could use the RequestMap to deny access based on attribute
values.

Short of ditching the federation metadata, and configuring
MetadataProviders for the specific IdPs we want to talk to, is there a way
to limit which IdPs it will permit authentication from?  Can will filter
out the unwanted IdPs somehow?

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130703/6ac4def6/attachment.html 


More information about the users mailing list