Filters and Rules
Cantor, Scott
cantor.2 at osu.edu
Mon Jul 21 10:16:47 EDT 2014
On 7/21/14, 10:00 AM, "Richard Genthner" <moose at symplicity.com> wrote:
>I have a question based on Filter, Rules and polices on my IDP. I have a
>SP for a third party vendor and we release businessCategory from our
>openldap setup. This attribute contains something like the following:
>Found the following attribute: businessCategory[splunk, jabber, mail,
>share, devwiki, saleswiki, supportwiki, fuse]
>I want to limit access to that SP only to people that have the
>businessCategory that is say fuse. How would I go about doing in that ?
You wouldn't, the SP would. Your job is to supply the attributes (and the
recommended way would be to define URIs and use eduPersonEntitlement to
represent that permission), but regardless of the attributes used, it's
meant to be the SP that enforces access control, not the IdP.
-- Scott
More information about the users
mailing list