Multiple IdPs without discovery
Ted O'Connor
toconnor at gmail.com
Thu Mar 20 13:18:10 EDT 2014
Correct. I am handling authorization separately.
On Thu, Mar 20, 2014 at 1:16 PM, Peter Schober
<peter.schober at univie.ac.at>wrote:
> * Ted O'Connor <toconnor at gmail.com> [2014-03-20 17:58]:
> > This seems to work for me now:
> [...]
> > require valid-user
> [...]
>
> Other than for authorization, yes:
>
> * Peter Schober <peter.schober at univie.ac.at> [2014-03-20 15:26]:
> > Avoiding discovery is one thing, you still need authorization rules
> > (otherwise someone successfully authenticated for one vhost could
> > still access any other vhost as long as her session was active).
>
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140320/dcbad9ed/attachment.html
More information about the users
mailing list