different AuthnContextClassRef for different discovered IDP

marangiom m.marangio at innova.puglia.it
Mon Jun 13 09:22:01 EDT 2016


Cantor, Scott E. wrote
> On 6/8/16, 8:56 AM, "users on behalf of marangiom" <

> users-bounces@

>  on behalf of 

> m.marangio at .puglia

> > wrote:
> 
>>would it make sense to try to modify shibboleth-ds instead and put this
kind
>>of logic in it?
> 
> Possibility I guess.
> 
> -- Scott
> 
> 
> -- 
> To unsubscribe from this list send an email to 

> users-unsubscribe@



Hi Scott.
I had a look at the discovery service code, and I believe it is not possible
(or it's just harder) to extend it to do what I need.

I decided simply to extend my idp, writing my own LoginHandler to handle the
2 onknown types of authContextClassReference...
It would be just like the standard usernamePassword login handler, but it
handles the new authContextClassReference type.

I'll then configure my handler.xml to include those two new handlers.

Thanks
Ciao
Marcello



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/different-AuthnContextClassRef-for-different-discovered-IDP-tp7625998p7626097.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list