IDP filtering SPs?
Bryan E. Wooten
bryan.wooten at utah.edu
Thu Jun 19 18:24:16 EDT 2014
So is 2.x more problematic? We are in new territory here.
-Bryan
From: Nate Klingenstein <ndk at internet2.edu<mailto:ndk at internet2.edu>>
Reply-To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Thursday, June 19, 2014 4:02 PM
To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: Re: IDP filtering SPs?
Bryan,
I swear I just some recent posts regarding filtering access to Sps at the Idp. Ie the SP thinks that authentication equals authorization so it is incumbent on the Idp to deny access.
You're probably thinking about the thread from my recent post to the dev@ list. June 4 MDT, "Stopping users for insufficient attributes at the IdP in v3".
In our case we a talking Box. We only want current staff/students to get accounts via Box "auto-provisoning". Apparently Box can't/won't use eduPerson affiliation to make the decision.
Anyway we need to reject logins where the user is not staff/affiliate. Does that make sense?
Looking for guidance.
I think the responses in that thread will guide you towards today's options, tomorrow's options, and a conversation to continue with SP's. A more precise question will help if you are left wondering anything.
Hope this helps,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140619/7ca34e6d/attachment.html
More information about the users
mailing list