How to make IDP "site sensitive" for eduPersonPrimaryAffiliation

Nate Klingenstein ndk at internet2.edu
Tue Nov 17 15:20:02 EST 2015


   Management would prefer that when a student goes to faculty.example.org<http://faculty.example.org/>, and gets redirected to our idp, that the IDP instead of authenticating (based on uid/password), just spin them into an infinite loop of authentication failed, or better yet, and error at the IDP saying "You're not allowed to go to the faculty website."

  What the heck should I be looking for in the Shib IDP docs?

Vindication?  I don’t know.

I think your options for doing this out of the box with IdPv2 are limited.  You can make any one of those things happen, but you’ll need a custom login handler or you’ll need to munge it into an existing login process somehow.

For IdPv3, there are more options available to you, but it’ll still take some configuration or implementation work because there’s such variety in these scenarios.

https://wiki.shibboleth.net/confluence/display/IDP30/AuthenticationConfiguration#AuthenticationConfiguration-FlowCancellation
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151117/8d9b27fc/attachment.html>


More information about the users mailing list