Attribute checking based on sp location

Eric Goodman Eric.Goodman at ucop.edu
Wed Oct 19 13:08:57 EDT 2016


>I didn't bother asking, but usually that means they're using separate accounts. 
>It turns out that after 20 years of hard work eliminating multiple accounts, 
>Gartner is now busy telling all of us that the solution to role-based access 
>control is separate accounts. It's a "thing" now.

Probably correct, and ugly sounding.

Another potential use case which is probably infrequent in Shib deployments, but seems to be generally on an uptick in other areas is implementing least privilege/privilege escalation management. If done during the IdP authentication, the authentication process could allow you to specify the roles that you need for your access; in such a case reauthing at the IdP could end up returning different attributes depending on how you specify your need.

(That's as much a troll to see if people are implementing variable-privilege management in their IdPs as it is a comment about what might actually be happening in this case.)

--- Eric


More information about the users mailing list