different AuthnContextClassRef for different discovered IDP

marangiom m.marangio at innova.puglia.it
Wed Jun 8 04:37:16 EDT 2016


Peter Schober wrote
> * marangiom <

> m.marangio at .puglia

> > [2016-06-08 09:54]:
>> Is it possible configure my SP to override AuthnContextClassRef and
>> set it to Z for every service only when the IDP D is selected via
>> discovery?
> 
> I don't think there's a setting anywhere to the effect of "if you send
> an(y) authn request to IDP D then always include a request for
> AuthnContextClassRef Z, too". Neither in the SP nor in the CDS.
> 
> I doubt there's a metadata extension to address that case either.
> 
> If you really only had 4 IDPs you could simply forgo use of an
> external IDP Discovery Service (which is overkill, IMO, and the Shib
> CDS is going away soon anyway) and simply hand-craft the
> session-initiating links into your SP(s) or application(s), each time
> including the "correct" auth context for each IDP.
> 
> -peter
> -- 
> To unsubscribe from this list send an email to 

> users-unsubscribe@


Thanks for the reply
that's a bad news...

So, if I understand, if I have app_service1, app_service2... app_service10
and IDP_A, IDP_B, IDP_C and IDP_D (they could increase in number, but not so
much), I have to configure 10*4 SessionInitiators or applications to handle
this situation?

Marcello



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/different-AuthnContextClassRef-for-different-discovered-IDP-tp7625998p7626001.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list