Deny user to access SP via IdP?
David Langenberg
davel at uchicago.edu
Thu Jun 12 13:20:34 EDT 2014
On Thu, Jun 12, 2014 at 11:15 AM, Tom Scavo <trscavo at gmail.com> wrote:
> On Thu, Jun 12, 2014 at 12:32 PM, Ian Rifkin <irifkin at brandeis.edu> wrote:
> >
> > My question is if it's possible for the IdP to do some kind of
> authorization
> > for specific SPs…
>
> Yes, for some use cases, this is the way to go. In the Library use
> case, for example, the campus is in the best position to determine if
> and when a user should have access to a library resource (according to
> whatever contract is in place), so it's not unreasonable for the IdP
> to send an eduPersonEntitlement that indicates whether the user should
> have access.
>
Yes, I run into this occasionally from time to time. My response is it's
impossible for me to block the user at the IdP, however, I can send you an
attribute indicating if the user is allowed. We usually go 2-3 rounds, but
eventually the vendors always find a solution that uses an authorizing
attribute value.
Dave
--
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140612/24e6f72d/attachment.html
More information about the users
mailing list