shib / saml protection for IoT

Cantor, Scott cantor.2 at osu.edu
Tue Mar 7 13:34:09 EST 2017


On 3/7/17, 1:28 PM, "users on behalf of Liam Hoekenga" <users-bounces at shibboleth.net on behalf of liamr at umich.edu> wrote:

> I guess I see it as kind of equivalent to "library walk-in" ePA use case.  I feel like that would get implemented for users using
> trusted devices.

I don't think that's been used much, but in any event, those kinds of services tend not to rely on any other attributes.

> The vendor in question in BlueJeans.  In my conversation with our video conferencing people, it appears as if the only way to
> make a device available to BlueJeans is to log in from it.  We have a need to make devices that are associated
> with places (not people) available to this system.  IP based authentication seems like it might be reasonable.

Yes, I'm just saying you still have to map that to an identity. The IdP doesn't think in terms of users, though, I've been very careful to keep to the term "subject".

-- Scott




More information about the users mailing list