Context Check Intercept (Login Intercept?) for managing account suspensions?

Cantor, Scott cantor.2 at osu.edu
Wed Aug 28 13:50:03 EDT 2019


On 8/28/19, 12:51 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:

> Hello, we do run openldap but I'm pretty sure we don't support password policy overlays. Can I prevent login (for all
> relaying parties) for suspended accounts using a Context Check Intercept that checks the value of the user's suspension
> attribute?

I wouldn't recommend it for reasons Keith already stated (an IdP is not normally the only consumer of an LDAP) but if you're asking how the IdP would do it, yes, that's the most expeditious way.

-- Scott




More information about the users mailing list