<div dir="ltr">Correct.  I am handling authorization separately.</div><div class="gmail_extra"><br><br><div class="gmail_quote">On Thu, Mar 20, 2014 at 1:16 PM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Ted O&#39;Connor &lt;<a href="mailto:toconnor@gmail.com">toconnor@gmail.com</a>&gt; [2014-03-20 17:58]:<br>
<div class="">&gt;  This seems to work for me now:<br>
</div>[...]<br>
&gt;     require valid-user<br>
[...]<br>
<br>
Other than for authorization, yes:<br>
<div class=""><br>
* Peter Schober &lt;<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>&gt; [2014-03-20 15:26]:<br>
</div><div class="">&gt; Avoiding discovery is one thing, you still need authorization rules<br>
&gt; (otherwise someone successfully authenticated for one vhost could<br>
</div>&gt; still access any other vhost as long as her session was active).<br>
<div class="HOEnZb"><div class="h5"><br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>