<span style="font-family: Arial;">Well so far I like the add an LDAP attribute for not in LDAP1 and drive your authz at your SP with that.<br><br>Beats messing with custom handlers and specific Authn context.<br><br><br>sent from mobile<br><br>----- Reply message -----<br>From: &quot;Brewer, Edward L&quot; &lt;lee.brewer@Vanderbilt.Edu&gt;<br>To: &quot;Shib Users&quot; &lt;users@shibboleth.net&gt;<br>Subject: Question on Login Handlers<br>Date: Thu, Aug 22, 2013 5:37 PM<br><br></span><br>Scott,<br><br><br>&gt;&gt;<br>&gt;&gt;I think Chris is right on the front side.. your LDAP2 specific app <br>&gt;&gt;could request a special handler. But, the PreviousSession handler is <br>&gt;&gt;where things run into issues and your LDAP2 group will have access to <br>&gt;&gt;stuff they should not.<br><br>&gt;The handler won&#39;t run if you&#39;re using specific AuthnContext classes in the request from the special apps.<br><br>Well, I am currently only using UserPassword and PreviousSession with no defaults listed on any relying parties.. so I think that means that it is set to use UserPasword if not requested(and it has been working that way). &nbsp;The application that we are integrating with is owned by us and can be controlled. &nbsp;Just looking for guidance on how to configure<br><br>&gt;You can&#39;t do any of this properly unless you configure the SPs, and in that case, you should simply be using attributes.<br><br>We have access to the SP.<br><br>&gt;The OP is in for a world of pain here and should simply tell them he&#39;ll supply attributes as needed to drive policy and require appropriate policy. This is authn == authz. It seems to be like smallpox; seemingly eradicated but now coming back due to a rise in new security staff coming from apparently questionably competent backgrounds.<br><br>Not sure what you are referring to above (or if it was aimed to us). &nbsp;In particular the phrasing authn == authz<br><br>Thanks,<br>Lee<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br><br><br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>