library-walk-in

Peter Schober peter.schober at univie.ac.at
Wed Mar 6 14:21:50 EST 2019


Follow-up to resolving only desired attributes for the technical
"walk-in users" account w/o having to worry about any other
(undesired) attributes that the resolver may hand out
indiscriminately:

* Cantor, Scott <cantor.2 at osu.edu> [2019-02-26 20:50]:
> I was imagining it mainly at the DataConnector layer as long as
> things are configured to gracefully handle the null cases (or you
> could supply alternative connectors as failovers that supply the
> specific static data for that identity).
> 
> Anyway, the main point was, if the NameID layer has no data to
> depend on, it won't run and doesn't need to be told not to.

I've now documented the process to do just that, without creating an
actual account in any source systems while preventing any
DataConnectors from running for that subject, as suggested by Scott:

https://wiki.univie.ac.at/display/federation/IP-Authentication

It does reference our own local documentation in a few places for
context and so is currently hosted within our own wiki but if there's
interest I can move this into the Shibboleth wiki somewhere, too.

Happy to answer questions about this on this list, esp if anything is
still unclear or wrong.

-peter


More information about the users mailing list