Shibboleth SP / LDAP groups / htaccess files

Brent Putman putmanb at georgetown.edu
Mon Mar 11 17:49:28 EDT 2019


On 3/11/19 4:23 PM, Lohr, Donald wrote:
> We read some Shib documentation for apache configuration that
> indicated the use of ldap groups died at apache 2.2.  We are running
> apache 2.4.
>
>

In addition to the Apache LDAP authZ module approach that is possible
with 2.4 as others have noted: if you can influence the config/behavior
of the IdP you could also do a completely native SAML approach, by
having the IdP assert an attribute that is the user's LDAP group
memberships, via the appropriate attribute resolver configuration.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190311/cbd299ff/attachment.html>


More information about the users mailing list