Questions regarding login handler

Juan Quintanilla jquin014 at fiu.edu
Wed Feb 5 13:13:06 EST 2014


Hi Scott,

So just to understand what you are saying, we can't tell a specific service provider to use a specific login handler to use for authentication.  In our case we have ldap and wanted to have a specific OU that contains the users that are allowed to access a certain SP and then have that SP use the login handler to point to that OU while still having our default login handler for everyone else.

I know that is not the best approach and it should be that we pass an attribute to them which they consume and can grant access but unfortunately they have not made that customization.

Thanks!

___________________
Juan Quintanilla
UTS - Enterprise Group
305-348-6573
jquin014 at fiu.edu
________________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Tuesday, February 4, 2014 1:46 PM
To: Shib Users
Subject: Re: Questions regarding login handler

On 2/4/14, 1:38 PM, "Juan Quintanilla" <jquin014 at fiu.edu> wrote:
>
>Has anyone currently configured shibboleth idp to use different ldap
>login handlers for specific service providers?

You can't, modulo doing something like using separate authentication
methods requested by the SPs, which is not practical for this purpose, or
writing a custom login handler.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list