Shib, groups, external users ....
Keith Hazelton
hazelton at wisc.edu
Wed Mar 6 14:01:35 EST 2013
Isn't that something you could handle via Shib SP config: supplementing IdP-delivered attribute assertions with those from another (local in this case) source?
--Keith
____________________
On Mar 6, 2013, at 12:54 , Steven Carmody <steven_carmody at brown.edu> wrote:
> Hi,
>
> We've deployed the latest MACE Grouper, and we'll soon have groups with
> "external" (non-Brown) members. We'll be creating user objects in our
> local ldap directory for these people (in a different OU from community
> members), and we'll be populating their isMemberOf attribute
> appropriately (based on the MACE Grouper groups they're a member of).
>
> Here's the Shib question, tho -- when these people access a resource
> here at Brown, we want their home IDP to assert some attributes and
> values (eg EPPN), and the Shib access control and the application will
> use those asserted values.
>
> However, we also want to use some values retrieved from that person's
> local ldap user object (eg for apache's access control). The best
> example of this is group membership -- we don't want that asserted by
> their home campus -- we want to retrieve it from the local ldap.
>
> Interestingly, our local VPN implementation (from F5) supports Federated
> access, and their policy engine does what I've just described. But, I
> can't figure out how to configure apache to do this -- I don't see how
> to configure the various apache ldap modules to do JUST this ....
>
> Any and all suggestions welcome!
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list