Attribute checking based on sp location
Cantor, Scott
cantor.2 at osu.edu
Wed Oct 19 13:14:01 EDT 2016
> Another potential use case which is probably infrequent in Shib
> deployments, but seems to be generally on an uptick in other areas is
> implementing least privilege/privilege escalation management. If done
> during the IdP authentication, the authentication process could allow you to
> specify the roles that you need for your access; in such a case reauthing at
> the IdP could end up returning different attributes depending on how you
> specify your need.
Haven't seen that so much as just step-up, requesting either a new login as presence proof or adding the second factor for specific functions. That obviously also fits within the OP's scenario, at least in theory. Getting that in place out of the box was the main focus of the 3.3 work.
-- Scott
More information about the users
mailing list