School me on hub and spoke federations

Leif Johansson leifj at sunet.se
Mon May 13 17:04:29 EDT 2013


On 05/13/2013 10:59 PM, Steve Thorpe wrote:
>> On 5/13/13 4:44 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:
>>
>>> Currently, we authenticate at the enterprise level - when a request comes
>>> in, we use the IDp's entityID to look up the associated account and log
>>> the user in under that, then use the user specific attributes to
>>> personalize the user's experience.
>>>   In this hub and spoke scenario, would I need to have an attribute
>>> passed that indicates the specific enterprise attempting access since I
>>> only have the single federation based entityID?
> Would using a multi-scoped IdP be appropriate to help handle the 
> multiple spokes?  In such a case, couldn't any scoped attribute be 
> adjusted according to which spoke it came from?
>
> SteveT
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
Yeah you have to declare multiple scopes (if you're using
scopes) in metadata. I've come across situations where that
wasn't done and it invariably leads to calamity.

However (as with any name-constraints-scheme) the more
scopes you have on a single IdP the higher the risk of
anything going wrong.

        Cheers Leif



More information about the users mailing list