robot access to SP website

Jerry Shipman jes59 at cornell.edu
Wed Jun 23 13:32:30 UTC 2021


Thank you for the responses.
In lieu of quoting everybody, I will try to summarize that feedback as:
 - do it by apache auth rules, not SP rules
 - or request a different AuthnContextClassRef by IP address 

That makes sense in this case...I can see doing something like "tell apache to require this htpasswd user or this cert from this IP address, or SAML otherwise". 
(I'm not 100% sure that it will work to do it based on IP...this is the age of cloudy amazon lambdas and whatnot. I am also worried that they might be using IIS. But I'll try it.)

I can think of other semi-reasonable use cases in which the capability to do this in the SAML would make sense, though. e.g.: "administrative users [in this given group or role] have to MFA, but end users can do whatever" or "students and employees have to MFA, but alumni can do whatever". 

Is it really true that there is no way to implement such requirements on the Shib SP? (I suspect we have some requirements like that lurking around here somewhere, also, and it would be helpful to know how best to handle them.)

Thanks again for your help,
Jerry






More information about the users mailing list