School me on hub and spoke federations

Steve Thorpe thorpe at mailbox.mcnc.org
Mon May 13 16:59:10 EDT 2013


> On 5/13/13 4:44 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:
>
>> Currently, we authenticate at the enterprise level - when a request comes
>> in, we use the IDp's entityID to look up the associated account and log
>> the user in under that, then use the user specific attributes to
>> personalize the user's experience.
>>   In this hub and spoke scenario, would I need to have an attribute
>> passed that indicates the specific enterprise attempting access since I
>> only have the single federation based entityID?

Would using a multi-scoped IdP be appropriate to help handle the 
multiple spokes?  In such a case, couldn't any scoped attribute be 
adjusted according to which spoke it came from?

SteveT


More information about the users mailing list