Shib, groups, external users ....

Steven Carmody steven_carmody at brown.edu
Wed Mar 6 13:54:29 EST 2013


Hi,

We've deployed the latest MACE Grouper, and we'll soon have groups with 
"external" (non-Brown) members. We'll be creating user objects in our 
local ldap directory for these people (in a different OU from community 
members), and we'll be populating their isMemberOf attribute 
appropriately (based on the MACE Grouper groups they're a member of).

Here's the Shib question, tho -- when these people access a resource 
here at Brown, we want their home IDP to assert some attributes and 
values (eg EPPN), and the Shib access control and the application will 
use those asserted values.

However, we also want to use some values retrieved from that person's 
local ldap user object (eg for apache's access control). The best 
example of this is group membership -- we don't want that asserted by 
their home campus -- we want to retrieve it from the local ldap.

Interestingly, our local VPN implementation (from F5) supports Federated 
access, and their policy engine does what I've just described. But, I 
can't figure out how to configure apache to do this -- I don't see how 
to configure the various apache ldap modules to do JUST this ....

Any and all suggestions welcome!


More information about the users mailing list