How to force a login from particular IdP when accessing specific folder?
ivan.krivyakov at thomsonreuters.com
ivan.krivyakov at thomsonreuters.com
Thu Aug 18 12:04:10 EDT 2016
I have one web site with several secure folders: secure/alpha, secure/beta, secure/prod. Each of these corresponds to its own IdP, with its own entity ID.
I have successfully configured Shibboleth to initiate a session with the proper IdP when the folder is accessed. However, once a session is established, the user gains access to ALL secure folders. For example, if I am logged in with my Alpha account, I get access to things in secure/prod and vice versa. This is not what I want: I need the folders to be completely independent, and I want Shibboleth to maintain multiple sessions: one for Alpha, one for Beta, and for Prod.
I tried multiple session initiators and "requireSessionWith" attribute in RequestMapper/Host/Path, but it seems to be ignored: a login with any of the initiators opens access to all secured folders.
How do I configure Shibboleth so it keeps Alpha, Beta, and Prod logins separate and opens new session for Prod even if Alpha session already exists? Do I need to setup multiple applications?
TIA,
Ivan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160818/f8ed4250/attachment.html>
More information about the users
mailing list