Where to hook in switching of user identity
Tom Scavo
trscavo at gmail.com
Fri Jun 24 17:19:46 EDT 2016
On Fri, Jun 24, 2016 at 4:33 PM, Eric Goodman <Eric.Goodman at ucop.edu> wrote:
>>So, with all this spoofing stuff, how do you deal with non-repudiation of the
>>spoofed accounts for auditors? Did you modify the logs/assertion to sufficiently
>>indicate to the SP and/or within the IdP that the particular authN event is being
>>spoofed by a particular identity?
>
> See my response to Walter: there's nothing to stop you from releasing both the "real" subject ID and the "impersonated" one to the SP, so it seems like delivered logging should be fine.
To do that, the SP has to be reconfigured to not do any scope-checking
on scoped attributes asserted by the IdP Proxy. In other words, the SP
must be reconfigured to explicitly support impersonation. In that
case, it's fair to say that the SP and IdP Proxy share the same
security domain.
Tom
More information about the users
mailing list