multi-tenant SP

Cantor, Scott cantor.2 at osu.edu
Thu Mar 23 19:24:22 UTC 2023


> Are you saying using ShibRequestSetting entityID does that (discards a
> shibboleth session with a non-matching entityID, and only then uses the
> specified entityID)?

No, it does not, nor does what you were doing. Discovery != authorization, no matter how you do it.

I'm saying application code can do authorization in addition to, or in lieu of, Apache require rules.

-- Scott




More information about the users mailing list