<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
There’s a long and sordid history of differential interpretations, policy languages, and attribute buckets. &nbsp;Ultimately, it’s up to the provider of the service to enforce rules, but when the rule is “authentication is authorization as far as we’re concerned”,
 the identity provider may find itself enforcing authorization decisions as part of the authentication flow.
<div class=""><br class="">
</div>
<div class="">We would still consider making the authorization decision at the SP to be the “correct” approach. &nbsp;Accommodating either will be, for better or worse, more easily done in IdPv3.<br class="">
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Dec 18, 2014, at 12:08 PM, Alex Olson &lt;<a href="mailto:ako@byu.edu" class="">ako@byu.edu</a>&gt; wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; font-size: 14px; font-family: Calibri, sans-serif;" class="">
<div class="">In Shibboleth/SAML protocol in general, who’s burden is it to determine whether or not principal X should be able to access some service, the IdP’s or the SP’s?</div>
<div class=""><br class="">
</div>
<div class="">I’d be inclined to think that the IdP is simply the releaser of attributes and the SP has the burden to use those attributes to determine whether or not the principal should be allowed access, but now we are being asked by a vendor to have our
 IdP bear the burden of authorization. What do you think? Should I push back? Is it even possible to have the IdP bear the burden of authorization?</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class="">
<div id="MAC_OUTLOOK_SIGNATURE" class="">
<div class="">
<div class="">--</div>
<div class="">Alex K. Olson</div>
</div>
</div>
</div>
</div>
-- <br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a></div>
</blockquote>
</div>
<br class="">
</div>
</div>
</body>
</html>