Better approach to do Authorization in shibboleth

Paul Hethmon paul.hethmon at clareitysecurity.com
Tue Dec 2 09:03:18 EST 2014


On Dec 2, 2014, at 6:59 AM, Surinaidu Majji <pioneer.suri at gmail.com<mailto:pioneer.suri at gmail.com>> wrote:

Thank you for your reply, but you are saying attributes pulled from resolver:
Is that attribute-resolver.xml, configured for releasing attributes, in that case
i am releasing 'principal' which contains 'permissions' to SP. Is that right?


attribute-resolver.xml defines attributes and the sources to obtain those attributes. That includes the “principal” and anything else you might define.

attribute-filter.xml defines which SP’s get which attributes released to them.

None of that is “permissions” in the sense that to the IdP the attributes are opaque values sent to an SP. There is no inherent meaning of those attributes at the IdP level. At the SP level it has to define what those attributes mean.

Paul



——

Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141202/129a7ab3/attachment-0001.html 


More information about the users mailing list