Shib, groups, external users ....

Christopher Bongaarts cab at umn.edu
Fri Mar 8 14:58:00 EST 2013


On 3/6/2013 1:26 PM, Cantor, Scott wrote:
> On 3/6/13 2:13 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote:
>
>> Right, front-ended with SAML, essentially a supplementary Attribute
>> Authority.  What's the quickest path to standing up such a thing if one
>> is familiar with Shib?  --Keith
>
> That's all there is, it's the same work minus having to do authentication
> setup.

One could also conceivably stand up (another) IdP that was also an SP to 
the existing IdPs to perform the aggregation function as an attribute 
resolution task.

Or write a shim Apache module that hooks after mod_shib and 
mod_authz_ldap to enforce the AND semantics.

Or do the LDAP authz step inside the app rather than the web server 
(which depends on the app...)

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the users mailing list