Attribute filter requirement based on client IP-address
Ian Young
ian at iay.org.uk
Mon May 6 09:55:31 EDT 2013
On 6 May 2013, at 14:21, Philip Brusten <philip.brusten at icts.kuleuven.be> wrote:
> I saw the UKFederation made an extension to the resolver, called User
> Agent Based Attributes, which made it possible to statically add
> SAML-attributes based on the client's IP-address.
Well, I wouldn't say "statically". The attribute names and values are static but the process as a whole depends on the client's IP address so I'd have said it was dynamic. The intention certainly wasn't to just stuff the IP address into an attribute.
> But I don't understand why they didn't use the attribute filter to accomplish this.
Again, I'm not quite sure what you are thinking of as an alternative, but the extension we built was intended as an easy to configure solution to a particular problem and I think it addresses the intended use case pretty well. Of course there will be other ways to solve the same or related problems.
Once you have used the extension to create attributes based on the client's IP address ("on the X network", "on campus", etc.), they don't necessarily have to be sent to the SP. That was the original usage pattern we had in mind but the extension creates IdP internal attributes and not necessarily SAML ones. You can use the attributes to drive IdP-side policy if that's what you want to do.
-- Ian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20130506/cb1f110d/attachment.bin
More information about the users
mailing list