SP configred to use multiple IdP's.
Cantor, Scott
cantor.2 at osu.edu
Mon Nov 9 16:43:59 EST 2015
On 11/9/15, 4:27 PM, "users on behalf of Brent Putman" <users-bounces at shibboleth.net on behalf of putmanb at georgetown.edu> wrote:
>Point of clarification: Isn't this this use case for the ApplicationOverride/MetadataProvider that someone was asking about a few weeks ago (and using in an erroneous manner, as it turned out)?
Yes.
> I thought I understood you to say that the main (legitimate) use case was to restrict usage to specific IdP(s), which sounds like what the OP wants to do here - trust only a specific IdP for purposes of the application boundary.
Yes, that is the case, but doing overrides by path is brutal, and in either case doing the authorization after the fact is a lot simpler in most cases when the set of IdPs is constrained.
The better model is to stick to authorization by attributes and/or authnContext/method if that's also required.
-- Scott
More information about the users
mailing list