<div dir="ltr">Hi Nate,<div><br></div><div> Thanks for your reply. I am, unfortunately, still lost here. I can see, from the docs, how it's supposed to work, but I can't figure out how to actually check the attribute. Basically, I am trying to check if the user is a member of a specific AD group. I do have this information coming into Shibboleth as I release the group list to other SP's for access control. I cannot figure out how to check group membership as part of the intercept though. </div><div><br></div><div> So basically, I'm looking for docs or an example of how to check group membership as part of the intercept. </div><div><br></div><div>Thanks</div><div>-Matt</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, May 3, 2016 at 5:07 PM, Nate Klingenstein <span dir="ltr"><<a href="mailto:ndk@sudonym.me" target="_blank">ndk@sudonym.me</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Matt,<br>
<br>
There’s an example that does this in a file in the distribution at $IDP_HOME/conf/intercept/context-check-intercept-config.xml. I think I could guess what to put in each of the fields. If part of that example is confusing, specific questions would probably be easier to answer.<br>
<br>
Congratulations on your yearly subscriptions,<br>
Nate.<br>
<div class="HOEnZb"><div class="h5"><br>
> On May 3, 2016, at 15:02, Matt Brennan <<a href="mailto:brennanma@gmail.com">brennanma@gmail.com</a>> wrote:<br>
><br>
> Thanks for the reply, Scott. I completely agree, but the SP in question doesn't do that ... and worse, they automatically charge me for a year subscription for every user that logs in via SSO.<br>
><br>
> I admit that I'm not very familiar with SWF. Has anyone else done this (or something close) that they could provide an example of? Mainly just the beans associated with the intercept.<br>
><br>
> Thanks<br>
><br>
> On Mon, May 2, 2016 at 5:27 PM, Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br>
> > I am trying to transition our remaining AD FS profiles over to Shibboleth (IDP<br>
> > 3). I am having an issue with one though - the particular SP is limited to<br>
> > specific users, based on AD group membership. I can't see to find docs on<br>
> > how to implement this is in Shibboleth. Can someone please point me in the<br>
> > right direction?<br>
><br>
> We don't generally consider that a function of the IdP, authz is up to the SP, with the IdP supplying the groups as attributes.<br>
><br>
> If you must, see [1].<br>
><br>
> -- Scott<br>
><br>
> [1] <a href="https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterceptConfiguration" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterceptConfiguration</a><br>
> --<br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
><br>
> --<br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div></blockquote></div><br></div>