Advice on controlling IDP 3 administrative functions

Cantor, Scott cantor.2 at osu.edu
Fri Apr 17 14:40:46 EDT 2015


On 4/17/15, 2:28 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 4/17/15, 2:18 PM, "Koch, Ken" <ken at wustl.edu> wrote:
>>My options as I see them:
>>-         
>>Rename administrative flows in IDP to obfuscate them
>>-         
>>Redirect rules on the F5 to dead-end the administrative urls
>>-         
>>Implement basic auth on admin urls somehow at the machine level
>
>Or...change the access policy on the admin functions you want to limit so it's not shared with the status page?

(Specifically, add new named policies with different address rules to access-control.xml and then alter the properties in idp.properties to reference them.)

We didn't expose enough fine grained control to do, say, different rules for every possible case, but service reload, the resolvertest tool, and status are all separate.

-- Scott



More information about the users mailing list