Better approach to do Authorization in shibboleth
Surinaidu Majji
pioneer.suri at gmail.com
Wed Dec 3 01:43:30 EST 2014
Hello Paul,
I am really very happy that i am getting lot of information from the Shib
Users like you, but i do not know why i am not able to get the exact
information which i required. I think i got the replies for my query but i
could able to understand properly.
Here my actual requirement is:
Now i am using shibboleth idp which we own(External Idp) to do
authentication. Here i use 'ExternalAuthn' Login handler in handler.xml.
Now the authentication is done by checking the credentials(from login.jsp)
with our *Server(database)*
- The current requirement is like instead of using our *Server *to validate
credentials(from login.jsp), i have to link this external idp to *other
Server (database).*
That's why i wanted know about authorization for my application, but i
could not able to achieve it.
Please consider my request, because i do not have any other source to
get my requirement done, If require i will post my entire authentication
procedural steps which i have right now in my existing application.
On Tue, Dec 2, 2014 at 7:33 PM, Paul Hethmon <
paul.hethmon at clareitysecurity.com> wrote:
> On Dec 2, 2014, at 6:59 AM, Surinaidu Majji <pioneer.suri at gmail.com>
> wrote:
>
>
> Thank you for your reply, but you are saying attributes pulled from
> resolver:
> Is that attribute-resolver.xml, configured for releasing attributes, in
> that case
> i am releasing 'principal' which contains 'permissions' to SP. Is that
> right?
>
>
> attribute-resolver.xml defines attributes and the sources to obtain
> those attributes. That includes the “principal” and anything else you might
> define.
>
> attribute-filter.xml defines which SP’s get which attributes released to
> them.
>
> None of that is “permissions” in the sense that to the IdP the
> attributes are opaque values sent to an SP. There is no inherent meaning of
> those attributes at the IdP level. At the SP level it has to define what
> those attributes mean.
>
> Paul
>
>
>
> ——
>
> Paul Hethmon
> Chief Software Architect
> paul.hethmon at clareitysecurity.com
>
>
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141203/da328638/attachment.html
More information about the users
mailing list