Denying users to login based on pattern in multiple auth flows

Simon Lundström simlu at su.se
Fri Feb 12 04:20:25 EST 2016


On Wed, 2016-02-10 at 01:18:45 +0000, Eric Goodman wrote:
> >Well, just to be compliant eduroam passwords needs not to be the same as our SAML federation, SWAMID in our case, 
> 
> Late response, but this caught my eye.
> 
> What kind of compliance are you referring to here? I don't know of and can't find anything in the eduroam or the SWAMID sites that would require the eduroam passwords be different from the SAML federation ones.

I was wrong. I talked to SWAMID operations and it's perfectly valid both
for AL1 and AL2 users to have the same username/password for eduroam and
SAML2.

In the past there were talks about putting it in the policy but it was
removed in the final versions apparently.

BR,
- Simon


More information about the users mailing list