Deny user to access SP via IdP?

David Langenberg davel at uchicago.edu
Thu Jun 12 13:20:34 EDT 2014


On Thu, Jun 12, 2014 at 11:15 AM, Tom Scavo <trscavo at gmail.com> wrote:

> On Thu, Jun 12, 2014 at 12:32 PM, Ian Rifkin <irifkin at brandeis.edu> wrote:
> >
> > My question is if it's possible for the IdP to do some kind of
> authorization
> > for specific SPs…
>
> Yes, for some use cases, this is the way to go. In the Library use
> case, for example, the campus is in the best position to determine if
> and when a user should have access to a library resource (according to
> whatever contract is in place), so it's not unreasonable for the IdP
> to send an eduPersonEntitlement that indicates whether the user should
> have access.
>

Yes, I run into this occasionally from time to time.  My response is it's
impossible for me to block the user at the IdP, however, I can send you an
attribute indicating if the user is allowed.  We usually go 2-3 rounds, but
eventually the vendors always find a solution that uses an authorizing
attribute value.

Dave

-- 
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140612/24e6f72d/attachment.html 


More information about the users mailing list