Impersonation in IDP

Cantor, Scott cantor.2 at osu.edu
Thu Aug 24 13:00:57 EDT 2017


On 8/24/17, 12:58 PM, "users on behalf of Greg Haverkamp" <users-bounces at shibboleth.net on behalf of gahaverkamp at lbl.gov> wrote:

> What information is Adobe actually looking for? Can you do most/all of this in the resolver, NameID machinery, and attribute
> filters, and just send Adobe the appropriate account information?  You're not really trying to delegate an "IdP account"; you're
> trying to delegate an account that relies on the IdP.

Thank you, that's definitely another strategy, yes. Attaching conditional logic or using scripts in various places would allow data to be remapped there, and of course it doesn't mean new work.

The main advantage of an interceptor is the UI. There's a possibility to plug in some policy chokepoints around which systems and identies are involved, and possibly even choose the impersonated identity, etc. More auditing potential too though that will be tricky in any event.

-- Scott




More information about the users mailing list