Attribute checking based on sp location
Cantor, Scott
cantor.2 at osu.edu
Wed Oct 19 09:35:58 EDT 2016
> * Cantor, Scott <cantor.2 at osu.edu> [2016-10-18 18:59]:
> > You don't really have to logout anyway. Just request a new login
> > from the IdP and it will replace the old one.
>
> My point (and I thought yours, too) was that if there's an SSO session
> with the IDP why would the subject be authorized to access the
> resource the second time around (assuming use of the same IDP)?
I didn't bother asking, but usually that means they're using separate accounts. It turns out that after 20 years of hard work eliminating multiple accounts, Gartner is now busy telling all of us that the solution to role-based access control is separate accounts. It's a "thing" now.
-- Scott
More information about the users
mailing list