<div dir="ltr"><div>Thank you for the discussion and feedback. I entered the feature request <a href="https://issues.shibboleth.net/jira/browse/IDP-784">https://issues.shibboleth.net/jira/browse/IDP-784</a><br><br><span class="im">>>I agree with fine grained authorization there is no
other way but to do authorization in the SP, but for general corporate
requirements doing it at the IDP is simpler to enforce at scale, and
just as important to audit at scale.<br>
</span>>Most major applications have so many back doors when it comes to
integrating SSO that the audit would have to be done at the application
anyway if it was to mean anything.<br></div><br>I agree with those issues, but even when you've proven to yourself the app/architecture is secure (not implying you only do this once) - someone still needs to regularly audit that the authorization policies to ensure they are inline with corporate policies, and corporate policies change so its a never ending job.<br><div>
</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Aug 6, 2015 at 2:31 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 8/6/15, 1:32 PM, "users on behalf of cneberg" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:cneberg@gmail.com">cneberg@gmail.com</a>> wrote:<br>
<br>
<br>
><br>
>I assume you mean any small changes to the context tree of the flow, as done by my code would break the the code of the flow (which is my goal) - so this is the path I should take if I need authorization in the IDP?<br>
<br>
</span>Yes, anything else would require an exhaustive security study of SWF, a penetration test, etc. I'm likely being very conservative in my assessment here but since I don't really know...<br>
<span class=""><br>
>I agree with fine grained authorization there is no other way but to do authorization in the SP, but for general corporate requirements doing it at the IDP is simpler to enforce at scale, and just as important to audit at scale.<br>
<br>
</span>Most major applications have so many back doors when it comes to integrating SSO that the audit would have to be done at the application anyway if it was to mean anything.<br>
<span class=""><br>
>So I guess I'm asking is - could there be a blessed way for developers who want to implement Authorization in the IDP to do it securely? Either the way you describe above - becomes the blessed way, OR some new API we could code to? I could open a case if this is something you are willing to discuss more.<br>
<br>
</span>If you want to request a feature for this, that's fine. I think we just need to implement a final gating step that prevents a response and document how to inform it.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>