SP Specific Test Accounts

Ramon Pfeiffer ramon.pfeiffer at uni-tuebingen.de
Fri Sep 8 02:28:23 EDT 2017


Hi Brandon,

you could define an activation condition for the attribute resolvers
that is only true if a regular user accesses any service or if the test
user accesses his specific service (in other words, that will always
return false if a test user tries to access a different SP).

That way, a test user accessing a different SP will get authenticated by
the IdP, but the IdP will serve an empty attribute set.

Our federation has a tutorial page on it [1] (only in German I fear).

Hope this helps,
Ramon

[1]: https://wiki.aai.dfn.de/de:shibidp3testzugang_fuer_externe_admins

--
Universität Tübingen
Zentrum für Datenverarbeitung
Wächterstraße 76
72074 Tübingen

E-Mail: ramon.pfeiffer at uni-tuebingen.de
Telefon: +49-7071-29-70213


On 07.09.2017 17:01, McKean, Brandon Scott - mckeanbs wrote:
> Hi Everyone,
> 
>  
> 
> We’re periodically asked for test accounts by vendors. Can anyone
> recommend a way to restrict an account’s access to a particular service
> provider from the IDP side?
> 
>  
> 
> I know of the context-check interceptor flow, but it looks like you’d
> essentially have to configure a flow to block the user that’s used by
> default and have one just for the service provider in question to allow
> access.
> 
>  
> 
> Thanks,
> 
> -- 
> 
> Brandon McKean
> 
> IT / Systems
> 
> Linux Administrator
> 
> (540)568-4235
> 
>  
> 
> 
> 

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5217 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170908/4f323dc4/attachment.p7s>


More information about the users mailing list