Deny access to RP based on Kerberos Realm

Katy Czar katrina.czar at uvm.edu
Tue Dec 10 16:03:11 UTC 2024


Hello,
I am currently migrating some custom Webauth scripts to a purely Shibboleth Kerberos implementation.  Part of the external Webauth flow prevented any user in our former student realm from accessing all but a few services.  I would like to implement this in Shibboleth, but I am unsure of the best way to do it.  Should this be done with an activation condition, or configured in the MFA login flow?  I have implemented the chaining of multiple Kerberos validators as described in this guide https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631614/KerberosAuthnConfiguration.

I am aware Webauth went EOL in 2018, I'm just trying to catch up on some major technical debt.

Thank you in advance!
__________________________________________________________________________________________
Katy Czar
Systems Architecture & Admin
University of Vermont
kczar at uvm.edu<mailto:kczar at uvm.edu>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241210/3ad1ca2c/attachment.htm>


More information about the users mailing list