<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Le 19/09/2017 à 11:06, Peter Schober a écrit :<br>
    <blockquote type="cite"
      cite="mid:20170919090641.abu6zaauqndouow5@aco.net">
      <pre wrap="">* Jacques Le Roux <a class="moz-txt-link-rfc2396E" href="mailto:jacques.le.roux@les7arts.com"><jacques.le.roux@les7arts.com></a> [2017-09-19 09:25]:
</pre>
      <blockquote type="cite">
        <pre wrap="">|<Location />|
|AuthType shibboleth|
|Require shibboleth|
|</Location>

I guess it's different than

<Location />
  AuthType shibboleth
  ShibRequestSetting requireSession 1
  require valid-user
</Location>
</pre>
      </blockquote>
      <pre wrap="">
Very. The latter actively prevents access to the whole vhost unless an
active session has been estblished ("requireSession" is set to
true). The former is merely a syntactical necessity for httpd to have
mod_shib "see" the request in order for it to provide any environment
variables set by mod_shib that may or may not exist yet.
I.e., the latter is access control, the former merely makes existing
session data avaiable to the server, but does not enforce anything.

</pre>
      <blockquote type="cite">
        <pre wrap="">I mean the 2nd form does not "||Overrides other Authentication Rules", right ?
</pre>
      </blockquote>
      <pre wrap="">
Not sure I understand. What is it you really want to know? What
combination with what other authz rules (from what modules) are you
having issues with?
-peter
</pre>
    </blockquote>
    Thanks Peter,<br>
    <br>
    Actually I have no issues, I just want to be sure that by using the
    2nd form I will not get any troubles like mentioned in a warning
    near the link  I provided.<br>
    Namely that by using the 2nd form I have not to worry about what the
    1st form does:<br>
    <br>
    <<Note that using a global rule as above will override and
    circumvent rules applied in <code><Directory></code> blocks
    or in local htaccess files. This includes both Shibboleth rules or
    rules for other authentication methods that might be in use. The
    above should <strong>only</strong> be used when the entire server
    is dedicated to hosting a single Shibboleth-enabled application that
    performs its own authorization.>><br>
    <br>
    I'm 99% sure, just need the last 1% confirmed :)  <br>
    <br>
    <pre class="moz-signature" cols="150">Jacques
</pre>
  </body>
</html>