Shib, groups, external users ....

Keith Hazelton hazelton at wisc.edu
Wed Mar 6 14:02:35 EST 2013


You presumably have an identifier coming in from the IdP that would allow you to find the corresponding local user info.   --k
______
On Mar 6, 2013, at 13:01 , Keith Hazelton <hazelton at wisc.edu> wrote:

> Isn't that something you could handle via Shib SP config: supplementing IdP-delivered attribute assertions with those from another (local in this case) source?
> 
>      --Keith
> ____________________
> On Mar 6, 2013, at 12:54 , Steven Carmody <steven_carmody at brown.edu> wrote:
> 
>> Hi,
>> 
>> We've deployed the latest MACE Grouper, and we'll soon have groups with 
>> "external" (non-Brown) members. We'll be creating user objects in our 
>> local ldap directory for these people (in a different OU from community 
>> members), and we'll be populating their isMemberOf attribute 
>> appropriately (based on the MACE Grouper groups they're a member of).
>> 
>> Here's the Shib question, tho -- when these people access a resource 
>> here at Brown, we want their home IDP to assert some attributes and 
>> values (eg EPPN), and the Shib access control and the application will 
>> use those asserted values.
>> 
>> However, we also want to use some values retrieved from that person's 
>> local ldap user object (eg for apache's access control). The best 
>> example of this is group membership -- we don't want that asserted by 
>> their home campus -- we want to retrieve it from the local ldap.
>> 
>> Interestingly, our local VPN implementation (from F5) supports Federated 
>> access, and their policy engine does what I've just described. But, I 
>> can't figure out how to configure apache to do this -- I don't see how 
>> to configure the various apache ldap modules to do JUST this ....
>> 
>> Any and all suggestions welcome!
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list