<div dir="ltr">Hello Paul,<div>I am really very happy that i am getting lot of information from the Shib Users like you, but i do not know why i am not able to get the exact information which i required. I think i got the replies for my query but i could able to understand properly.</div><div><br></div><div>Here my actual requirement is:</div><div>Now i am using shibboleth idp which we own(External Idp) to do authentication. Here i use &#39;ExternalAuthn&#39; Login handler in handler.xml. Now the authentication is done by checking the credentials(from login.jsp) with our <b>Server(database)</b></div><div><br></div><div>- The current requirement is like instead of using our <b>Server </b>to validate credentials(from login.jsp), i have to link this external idp to <b>other Server (database).</b></div><div>That&#39;s why i wanted know about authorization for my application, but i could not able to achieve it.</div><div>Please consider my request, because i do not have any other source to get my requirement done, If require i will post my entire authentication procedural steps which i have right now in my existing application.<b> </b></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Dec 2, 2014 at 7:33 PM, Paul Hethmon <span dir="ltr">&lt;<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



<div style="word-wrap:break-word"><span class="">
On Dec 2, 2014, at 6:59 AM, Surinaidu Majji &lt;<a href="mailto:pioneer.suri@gmail.com" target="_blank">pioneer.suri@gmail.com</a>&gt; wrote:<br>
<div>
<blockquote type="cite"><br>
<div>
<div dir="ltr" style="font-family:Helvetica;font-size:14px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
<div>Thank you for your reply, but you are saying attributes pulled from resolver:</div>
<div>Is that attribute-resolver.xml, configured for releasing attributes, in that case</div>
<div>i am releasing &#39;principal&#39; which contains &#39;permissions&#39; to SP. Is that right?</div>
</div>
<br>
</div>
</blockquote>
</div>
<div><br>
</div>
</span><div>attribute-resolver.xml defines attributes and the sources to obtain those attributes. That includes the “principal” and anything else you might define.</div>
<div><br>
</div>
<div>attribute-filter.xml defines which SP’s get which attributes released to them.</div>
<div><br>
</div>
<div>None of that is “permissions” in the sense that to the IdP the attributes are opaque values sent to an SP. There is no inherent meaning of those attributes at the IdP level. At the SP level it has to define what those attributes mean.</div>
<div><br>
</div>
<div>Paul </div>
<div><br>
</div>
<div><br>
</div>
<br>
<div>——<span class="HOEnZb"><font color="#888888"><br>
<br>
Paul Hethmon<br>
Chief Software Architect<br>
<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a><br>
<br>
<br>
</font></span></div>
<br>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>