Burden of Authorization

Peter Schober peter.schober at univie.ac.at
Thu Dec 18 14:22:46 EST 2014


* Alex Olson <ako at byu.edu> [2014-12-18 20:10]:
> In Shibboleth/SAML protocol in general, who’s burden is it to
> determine whether or not principal X should be able to access some
> service, the IdP’s or the SP’s?

It's in the interest of the resouce owner (i.e., SP) to make sure only
authorized subjects are accessing protected resources.
Not surprisingly it's also the resource owner who is in the unique
position to enforce access control rules controlling access to its
resources.
The IDP merely feeds data (attributes) into the SP's access control
decisions, including the case of not sending the agreed upon
attributes for unauthorized subjects -- or not any attributes at all.
-peter


More information about the users mailing list