Configuring two applications within one Shibboleth installation
Maassen, Helma
Helma.Maassen at atos.net
Thu Jun 13 03:26:53 EDT 2013
hi,
I needed to think this over for a bit :-)
What I didn't mention before is that my SPs also need to be different for the two IDPs, so a different Issuer in the AuthnRequest, probably a different TrustEngine, probably even a different AssertionConsumerService "type".
So I would love to use your solution but I think I cannot make it work using only apache-vhost configuration.
Helma.
________________________________________
From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Peter Schober [peter.schober at univie.ac.at]
Sent: 13 June 2013 08:56
To: users at shibboleth.net
Subject: Re: Configuring two applications within one Shibboleth installation
* Peter Schober <peter.schober at univie.ac.at> [2013-06-13 08:51]:
> * Maassen, Helma <Helma.Maassen at atos.net> [2013-06-13 08:44]:
> > I think I need the override in this case.
>
> E.g. like this:
>
> <Location /loket/bedrijf>
> AuthType Shibboleth
> ShibRequestSetting requireSession 1
> Require valid-user
> # Force use of IdP1
> ShibRequestSetting entityID <IDP1>
> </Location>
The working on the comment ("force use of IDP1") might be misleading
and obviously I skipped over the authorization part above. If none of
the subjects coming in via IdP1 are allowed in /loket/borger (and vice
versa) you'll need to put proper authorization rules into these
location directives (or handle it inside the application).
While you could do that by making them seperate logical SPs and have
each of them only know a subset of IdPs (excluding the "other" ones
every time; i.e., access control via metadata censoring) that seems
overly complicated to me,
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
Dit bericht is vertrouwelijk en kan geheime informatie bevatten enkel bestemd voor de geadresseerde. Indien dit bericht niet voor u is bestemd, verzoeken wij u dit onmiddellijk aan ons te melden en het bericht te vernietigen. Aangezien de integriteit van het bericht niet veilig gesteld is middels verzending via internet, kan Atos Nederland B.V. niet aansprakelijk worden gehouden voor de inhoud daarvan. Hoewel wij ons inspannen een virusvrij netwerk te hanteren, geven wij geen enkele garantie dat dit bericht virusvrij is, noch aanvaarden wij enige aansprakelijkheid voor de mogelijke aanwezigheid van een virus in dit bericht. Op al onze rechtsverhoudingen, aanbiedingen en overeenkomsten waaronder Atos Nederland B.V. goederen en/of diensten levert zijn met uitsluiting van alle andere voorwaarden de Leveringsvoorwaarden van Atos Nederland B.V. van toepassing. Deze worden u op aanvraag direct kosteloos toegezonden.
This e-mail and the documents attached are confidential and intended solely for the addressee; it may also be privileged. If you receive this e-mail in error, please notify the sender immediately and destroy it. As its integrity cannot be secured on the Internet, the Atos Nederland B.V. group liability cannot be triggered for the message content. Although the sender endeavours to maintain a computer virus-free network, the sender does not warrant that this transmission is virus-free and will not be liable for any damages resulting from any virus transmitted. On all offers and agreements under which Atos Nederland B.V. supplies goods and/or services of whatever nature, the Terms of Delivery from Atos Nederland B.V. exclusively apply. The Terms of Delivery shall be promptly submitted to you on your request.
Atos Nederland B.V. / Utrecht
KvK Utrecht 30132762
More information about the users
mailing list