different AuthnContextClassRef for different discovered IDP

marangiom m.marangio at innova.puglia.it
Wed Jun 8 08:56:36 EDT 2016


Peter Schober wrote
> * marangiom <

> m.marangio at .puglia

> > [2016-06-08 10:38]:
>> So, if I understand, if I have app_service1, app_service2...
>> app_service10
>> and IDP_A, IDP_B, IDP_C and IDP_D (they could increase in number, but not
>> so
>> much), I have to configure 10*4 SessionInitiators or applications to
>> handle
>> this situation?
> 
> I'm just saying I don't see where/how you'd add such configuration
> details (3-tuples of: entityID-contentsetting-value or 2-tuples of
> entityID-authContextClassRef) to the Shibboleth SP.
> The SP does allow you to create those requests (or you can create them
> yourself in your application, esp if you don't need them to be
> signed), but knowing what to send where currently would need to be
> part of your application.
> -peter
> -- 
> To unsubscribe from this list send an email to 

> users-unsubscribe@

I was hoping to have zero impacto on the existing applications ...
would it make sense to try to modify shibboleth-ds instead and put this kind
of logic in it?
thanks
M



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/different-AuthnContextClassRef-for-different-discovered-IDP-tp7625998p7626005.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list