Shib, groups, external users ....

Keith Hazelton hazelton at wisc.edu
Wed Mar 6 14:01:35 EST 2013


Isn't that something you could handle via Shib SP config: supplementing IdP-delivered attribute assertions with those from another (local in this case) source?

      --Keith
____________________
On Mar 6, 2013, at 12:54 , Steven Carmody <steven_carmody at brown.edu> wrote:

> Hi,
> 
> We've deployed the latest MACE Grouper, and we'll soon have groups with 
> "external" (non-Brown) members. We'll be creating user objects in our 
> local ldap directory for these people (in a different OU from community 
> members), and we'll be populating their isMemberOf attribute 
> appropriately (based on the MACE Grouper groups they're a member of).
> 
> Here's the Shib question, tho -- when these people access a resource 
> here at Brown, we want their home IDP to assert some attributes and 
> values (eg EPPN), and the Shib access control and the application will 
> use those asserted values.
> 
> However, we also want to use some values retrieved from that person's 
> local ldap user object (eg for apache's access control). The best 
> example of this is group membership -- we don't want that asserted by 
> their home campus -- we want to retrieve it from the local ldap.
> 
> Interestingly, our local VPN implementation (from F5) supports Federated 
> access, and their policy engine does what I've just described. But, I 
> can't figure out how to configure apache to do this -- I don't see how 
> to configure the various apache ldap modules to do JUST this ....
> 
> Any and all suggestions welcome!
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list