IDP4 proxied IDP affiliation

Cantor, Scott cantor.2 at osu.edu
Tue Oct 6 19:46:24 UTC 2020


On 10/6/20, 3:41 PM, "users on behalf of Jerry Bailie" <users-bounces at shibboleth.net on behalf of jebailie at vassar.edu> wrote:

>    Control which (some/all) groups/roles/affiliations can log into a SP.

It's not unique to proxying, the ContextCheck intercept supports authz at the IdP.

> If I'm in the student role by affiliation, and an SP only wants, say, faculty to log in, how to disallow those in the 'student'
> group?

The correct answer in our view is "you give them the attributes and they do their job because it's their service", but if you want to do authz at the IdP, that feature is [1].

-- Scott

[1] https://wiki.shibboleth.net/confluence/display/IDP4/ContextCheckInterceptConfiguration



More information about the users mailing list