Deny user to access SP via IdP?

Peter Schober peter.schober at univie.ac.at
Thu Jun 12 15:01:41 EDT 2014


* Ian Rifkin <irifkin at brandeis.edu> [2014-06-12 18:33]:
> Is it possible to not send *anything* back to the SP for users that
> match a PolicyRequirementRule (for a given SP /
> AttributeRequesterString)?

Others had to deal with such SPs in the past the same way, so you're
definitively not alone on this. Here's what you could use:
http://shibboleth.net/pipermail/users/2012-June/004196.html

The Github links from that post are broken now, those two repositories
seem to live here now:
https://github.com/Unicon/Shibboleth-IDP-Postlogin-Filter
https://github.com/Unicon/Shibboleth-IDP-Postlogin-Flow

I've not had to use that myself but obviously others have and Keith
and Unicon folks are on this list, of course.
-peter


More information about the users mailing list