Shib, groups, external users ....
Christopher Bongaarts
cab at umn.edu
Fri Mar 8 14:58:00 EST 2013
On 3/6/2013 1:26 PM, Cantor, Scott wrote:
> On 3/6/13 2:13 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote:
>
>> Right, front-ended with SAML, essentially a supplementary Attribute
>> Authority. What's the quickest path to standing up such a thing if one
>> is familiar with Shib? --Keith
>
> That's all there is, it's the same work minus having to do authentication
> setup.
One could also conceivably stand up (another) IdP that was also an SP to
the existing IdPs to perform the aggregation function as an attribute
resolution task.
Or write a shim Apache module that hooks after mod_shib and
mod_authz_ldap to enforce the AND semantics.
Or do the LDAP authz step inside the app rather than the web server
(which depends on the app...)
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list