Shib, groups, external users ....
Steven Carmody
steven_carmody at brown.edu
Wed Mar 6 13:54:29 EST 2013
Hi,
We've deployed the latest MACE Grouper, and we'll soon have groups with
"external" (non-Brown) members. We'll be creating user objects in our
local ldap directory for these people (in a different OU from community
members), and we'll be populating their isMemberOf attribute
appropriately (based on the MACE Grouper groups they're a member of).
Here's the Shib question, tho -- when these people access a resource
here at Brown, we want their home IDP to assert some attributes and
values (eg EPPN), and the Shib access control and the application will
use those asserted values.
However, we also want to use some values retrieved from that person's
local ldap user object (eg for apache's access control). The best
example of this is group membership -- we don't want that asserted by
their home campus -- we want to retrieve it from the local ldap.
Interestingly, our local VPN implementation (from F5) supports Federated
access, and their policy engine does what I've just described. But, I
can't figure out how to configure apache to do this -- I don't see how
to configure the various apache ldap modules to do JUST this ....
Any and all suggestions welcome!
More information about the users
mailing list