limiting which IdPs can access an SP
Peter Schober
peter.schober at univie.ac.at
Thu Jul 4 05:32:00 EDT 2013
* Liam Hoekenga <liamr at umich.edu> [2013-07-03 22:13]:
> Short of ditching the federation metadata, and configuring
> MetadataProviders for the specific IdPs we want to talk to, is there
> a way to limit which IdPs it will permit authentication from? Can
> will filter out the unwanted IdPs somehow?
Implement proper authorization in the service (or SP)?
(You know, the old "authentication != authorized" adage?)
Unless this is a special case where positively /any/ credential valid
(think guest accounts etc.) at one of the whitelisted IDPs should be
able to access your service.
-peter
More information about the users
mailing list