Shib, groups, external users ....

Peter Schober peter.schober at univie.ac.at
Wed Mar 6 15:03:17 EST 2013


* Cantor, Scott <cantor.2 at osu.edu> [2013-03-06 19:59]:
> On 3/6/13 1:54 PM, "Steven Carmody" <steven_carmody at brown.edu> wrote:
> >Interestingly, our local VPN implementation (from F5) supports Federated
> >access, and their policy engine does what I've just described. But, I
> >can't figure out how to configure apache to do this -- I don't see how
> >to configure the various apache ldap modules to do JUST this ....
> 
> I don't know if you really can in 2.2, they added that more explicitly to
> 2.4. It definitely won't work well combining rules. You can't do things
> like require all of the rules across all modules to be met, it just
> doesn't allow for that in the design.

I'm pretty sure I've used Shib for authN and mod_authnz_ldap for
authorization in the past. (Also I recall Wes Craig? of Umich having
patches available for httpd for some of that).
If that fits the picture I can try to look for any old configs but no
promises, it's been many years since I've last used that.
-peter


More information about the users mailing list