Attribute filter requirement based on client IP-address

Philip Brusten philip.brusten at icts.kuleuven.be
Mon May 6 09:21:24 EDT 2013


Hi,

First of all, I hate to ask this question, because I think it's archaic 
to authorize based on IP-addresses, but for some reason vendors still 
don't allow off-campus access to their resources.

I saw the UKFederation made an extension to the resolver, called User 
Agent Based Attributes, which made it possible to statically add 
SAML-attributes based on the client's IP-address.  But I don't 
understand why they didn't use the attribute filter to accomplish this.

So I was wondering if it is possible to filter the attributes based on 
the client's IP-address in the PolicyRequirementRule.
I thought I could accomplish this with 
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPFilterRequirementScript, 
but the ShibbolethFilteringContext doesn't seem to provide access to the 
IP-address of the client, am I right?

Regards,

Philip







More information about the users mailing list