Limiting admin identities to selected SPs
Douglas E. Engert
deengert at anl.gov
Mon Jun 3 17:34:49 EDT 2013
Is there a way in the IDP-2.3.8 using the attribute-resolver and/or attribute-filter
to return the StatusCode for the response to an Assertion for selected valid users
to something other then:
urn:oasis:names:tc:SAML:2.0:status:Success?
I can see how to not send any attributes or NameIDs, but would like to
send something like:
urn:oasis:names:tc:SAML:2.0:status:Responder
with possibly one of these:
urn:oasis:names:tc:SAML:2.0:status:RequestDenied
urn:oasis:names:tc:SAML:2.0:status:RequestUnsupported
or some other code negative code.
We would like to control which SPs some users can authenticate to,
in particular, a user who has admin rights on a cloud vendor's site
can only use that identity to that site.
We don't want the user being able to register one of these admin identities
on some other unrelated SP.
--
Douglas E. Engert <DEEngert at anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
More information about the users
mailing list