Can a single SP front multiple disparate applications?
Tom Scavo
trscavo at gmail.com
Sun Sep 8 11:33:21 EDT 2013
On Sat, Sep 7, 2013 at 12:30 PM, David Langenberg <davel at uchicago.edu> wrote:
> as a stop-gap, here comes eduPersonEntitlement and a
> Scripted Attribute. Same idea, except you have the IdP plug-in to the
> source systems, build up the logic in the IdP & then express the
> authorization as an eduPersonEntitlement.
Yes, as long as the IdP that's authenticating the user is in the same
security domain as the authz source system. This is mostly true today
but it is becoming less and less so in a highly distributed,
cloud-based, outsourced world. For instance, we have two apps that
rely on an IdP instance hosted in the Amazon cloud (no authorization).
One of those apps is highly distributed, with authn IdP in the cloud
and authz AA in a partner security domain. So we have no choice but to
architect for logically separate authn and authz sources of authority.
Tom
More information about the users
mailing list