IDP4 proxied IDP affiliation
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 6 19:46:24 UTC 2020
On 10/6/20, 3:41 PM, "users on behalf of Jerry Bailie" <users-bounces at shibboleth.net on behalf of jebailie at vassar.edu> wrote:
> Control which (some/all) groups/roles/affiliations can log into a SP.
It's not unique to proxying, the ContextCheck intercept supports authz at the IdP.
> If I'm in the student role by affiliation, and an SP only wants, say, faculty to log in, how to disallow those in the 'student'
> group?
The correct answer in our view is "you give them the attributes and they do their job because it's their service", but if you want to do authz at the IdP, that feature is [1].
-- Scott
[1] https://wiki.shibboleth.net/confluence/display/IDP4/ContextCheckInterceptConfiguration
More information about the users
mailing list