Shibboleth SP / LDAP groups / htaccess files
Brent Putman
putmanb at georgetown.edu
Mon Mar 11 17:49:28 EDT 2019
On 3/11/19 4:23 PM, Lohr, Donald wrote:
> We read some Shib documentation for apache configuration that
> indicated the use of ldap groups died at apache 2.2. We are running
> apache 2.4.
>
>
In addition to the Apache LDAP authZ module approach that is possible
with 2.4 as others have noted: if you can influence the config/behavior
of the IdP you could also do a completely native SAML approach, by
having the IdP assert an attribute that is the user's LDAP group
memberships, via the appropriate attribute resolver configuration.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190311/cbd299ff/attachment.html>
More information about the users
mailing list