Restricting federations

Tim Murphy tim.murphy at ichec.ie
Sat Feb 23 10:20:35 EST 2019


Hi all,

We have 3 main types of users in our LDAP directory in separate OUs:
- Staff
- Members
- Inactive

At present our Shibboleth IdP is configure to search our LDAP Directory 
for staff only (Data Connector ldap filter). The service providers we 
use at present are for staff only. We are also a member of multiple 
inter federations which staff should only have access to. This works 
fine and is fairly straightforward.

However, we need to permit Members (i.e. not staff) access to some 
internal SPs, but not any inter federations

I'm sure this has been done before, any suggestions are welcome?


Regards,

Tim.
-- 
Tim Murphy
ICHEC Systems Team


More information about the users mailing list