Multiple IdPs without discovery

Ted O'Connor toconnor at gmail.com
Thu Mar 20 13:18:10 EDT 2014


Correct.  I am handling authorization separately.


On Thu, Mar 20, 2014 at 1:16 PM, Peter Schober
<peter.schober at univie.ac.at>wrote:

> * Ted O'Connor <toconnor at gmail.com> [2014-03-20 17:58]:
> >  This seems to work for me now:
> [...]
> >     require valid-user
> [...]
>
> Other than for authorization, yes:
>
> * Peter Schober <peter.schober at univie.ac.at> [2014-03-20 15:26]:
> > Avoiding discovery is one thing, you still need authorization rules
> > (otherwise someone successfully authenticated for one vhost could
> > still access any other vhost as long as her session was active).
>
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140320/dcbad9ed/attachment.html 


More information about the users mailing list