IP range protection and IT accounts for external users
Matthew Slowe
m.slowe at kent.ac.uk
Tue Sep 6 08:49:10 EDT 2016
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Wed, Aug 31, 2016 at 08:12:00AM +0000, Morrow, David wrote:
> Currently we provide IT accounts for external contractors and temporary
> guests to the University. The accounts reside in a specific AD OU which is
> denied to the LDAP account used by Shibboleth to stop access to resources
> which use LDAP authentication.
>
> However, some e-journal sites use IP address range only for validation.
> Can I ask how other institutions deal with their "external" users and
> access to IP range protected resources? Apologies if this is the wrong
> list.
Hi David,
Drifting firmly offtopic from a Shibboleth list more into the general
access to eresources!
I'd start with Peter's suggestions of coaxing services towards a SAML2
AuthNZ model however some are just not capable or willing to do so. For
these cases, we use ezproxy as a proxy instead and only permit
"authorised users" to sign into ezproxy (using SAML2 as it happens) then
the upstream service only trusts the ezproxy IP addresses rather than
our entire campus network.
This was a bit of a bump for some onsite users who had to change from
going direct to going via ezproxy but it wasn't too bad.
Other options could include an authenticated web proxy restricted to
users in a given AD OU or Group (I'd definitely favour groups rather
than OUs).
- --
Matthew Slowe | Server Infrastructure Officer
IT Infrastructure, Information Services, University of Kent
Room S21, Cornwallis South
Canterbury, Kent, CT2 7NZ, UK
Tel: +44 (0)1227 824265
www.kent.ac.uk/is | @UnikentUnseenIT | @UKCLibraryIt
PGP: https://keybase.io/fooflington
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)
iEYEARECAAYFAlfOu0UACgkQ/V1qDCaTXgfyxgCgpK0KVc1sIigKMDvkE8NOMkZh
tRgAoLQsjmIh4h/R4Ud0RWvpZNos99hy
=g5iI
-----END PGP SIGNATURE-----
More information about the users
mailing list