Limiting admin identities to selected SPs

Douglas E. Engert deengert at anl.gov
Mon Jun 3 17:34:49 EDT 2013


Is there a way in the IDP-2.3.8 using the attribute-resolver and/or attribute-filter
to return the StatusCode for the response to an Assertion for selected valid users
to something other then:
   urn:oasis:names:tc:SAML:2.0:status:Success?

I can see how to not send any attributes or NameIDs, but would like to
send something like:
   urn:oasis:names:tc:SAML:2.0:status:Responder
with possibly one of these:
   urn:oasis:names:tc:SAML:2.0:status:RequestDenied
   urn:oasis:names:tc:SAML:2.0:status:RequestUnsupported
or some other code negative code.

We would like to control which SPs some users can authenticate to,
in particular, a user who has admin rights on a cloud vendor's site
can only use that identity to that site.

We don't want the user being able to register one of these admin identities
on some other unrelated SP.

-- 

  Douglas E. Engert  <DEEngert at anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444


More information about the users mailing list