Can Shib 3 deny access to certain SPs based on a user attribute?

Rod Widdowson rdw at steadingsoftware.com
Thu Oct 15 11:49:24 EDT 2015


Not sure if it's what you mean, but you can control what attributes (if any)
are release to any individual SP on the basis of the values of any
individual attribute.

After that it would be for the SP to do the "right thing" particularly with
respect to failing in a fashion which makes it obvious why they have failed.
It’s the SP's responsibility after all.

Other than that, as David said it's frowned upon to terminate a session at
the IdP because of AuthZ decisions (which are not the IdPs to take).  But
given a script you can always manage something.

/R




More information about the users mailing list