<div dir="ltr"><div><div><div><div><div><div>Hi all,<br><br></div>I've got a use case for a SAML extension for Shibboleth, and wondered if it is better discussing here or on the SAML list first, given that my default implementation would be Shibboleth.<br><br></div>I've been nibbling around the edges of integrating federated identities with SSH. My thought process to date is that this should be handled by teaching SSH to handle SAML, however it occurs to me that as long as the SSH server has a mechanism to perform an authorisation check for an identifiy/key combination, this can be tackled as a server-side issue, hopefully resulting in wider implementation sooner.<br><br></div>So, what I'm interested in adding is a mechanism for attribute/authorisation verification for a known set of data - e.g. a query for validity of a given subject,atribute,attribute value combination. This would allow, for example, collection of SSH public keys via web logins (either as released attributes or on a configuration page), and for verification of validity on every use of the private key.<br><br></div>An alternate use case would be for validating sign-up data, so that manually collected attributes can be verified. For example, if the IdP authenticates a user, but doesn't release attributes for the real name, it would be useful for the SP to confirm that a subject is who they claim to be on the sign-up page.<br><br></div>Best wishes,<br><br></div>Phil Lello<br></div>