<html><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /></head><body style='font-size: 10pt; font-family: Verdana,Geneva,sans-serif'>
<p>Good afternoon,</p>
<p>that v2 configuration allowed only users that are in the group ''IDP_Group" authorize to our idp when they're accessing to some/anyone SP. We wanted only some users to authorize, not all users in our windows AD.</p>
<p>Thanks and best regards</p>
<p>J.Karliak</p>
<p><br /></p>
<p><br /></p>
<div id="signature">---<br />
<div class="pre" style="margin: 0; padding: 0; font-family: monospace">Bc. Josef Karliak <br />Správa sítě a elektronické pošty<br />Fakultní nemocnice Hradec Králové<br />Odbor výpočetních systémů<br />Sokolská 581, 500 05 Hradec Králové<br />Tel.: +420 495 833 931, Mob.: +420 724 235 654<br />e-mail: <a href="mailto:josef.karliak@fnhk.cz">josef.karliak@fnhk.cz</a>, <a href="http://www.fnhk.cz" target="_blank" rel="noopener noreferrer">http://www.fnhk.cz</a>  <br />XMPP/Jabber : <a href="mailto:chosinek@jabb.im">chosinek@jabb.im</a></div>
</div>
<p><br /></p>
<p id="reply-intro">Dne 2021-03-04 14:38, Peter Schober napsal:</p>
<blockquote type="cite" style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0">
<div class="pre" style="margin: 0; padding: 0; font-family: monospace">* Josef Karliak via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> [2021-03-04 07:38]:
<blockquote type="cite" style="padding: 0 0.4em; border-left: #1010ff 2px solid; margin: 0"> on old shibboleth idp2 we used to allow users only in some Windows AD<br />group to authorize, is it able too in shibboleth idp 4 ?<br /><br /> On v2 :<br /><br />authorizationFilter="(memberOf=CN=IDP_Group,CN=Users,DC=domain,DC=local)"</blockquote>
<br />I can't remember what that setting did.<br />What exactly do you mean with "authorize" users to your IDP?<br />Supplying an LDAP search filter that prevents any NOT matching the<br />filter from using the IDP?<br /><br />Or is this in relation to a specific set of SPs (i.e., you'd want to<br />prevent the non-matching subjects from accessing those SPs but can<br />access anything else as far as your IDP is concerned)?<br /><br />For the former it's idp.authn.LDAP.userFilter in conf/ldap.properties<br /><br />Documentation for that can be found via<br />IDP4 wiki home page -> Configuration -> Authentication -> Password -> LDAP:<br /><a href="https://wiki.shibboleth.net/confluence/display/IDP4/Configuration" target="_blank" rel="noopener noreferrer">https://wiki.shibboleth.net/confluence/display/IDP4/Configuration</a><br /><a href="https://wiki.shibboleth.net/confluence/display/IDP4/AuthenticationConfiguration" target="_blank" rel="noopener noreferrer">https://wiki.shibboleth.net/confluence/display/IDP4/AuthenticationConfiguration</a><br /><a href="https://wiki.shibboleth.net/confluence/display/IDP4/PasswordAuthnConfiguration" target="_blank" rel="noopener noreferrer">https://wiki.shibboleth.net/confluence/display/IDP4/PasswordAuthnConfiguration</a><br /><a href="https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration" target="_blank" rel="noopener noreferrer">https://wiki.shibboleth.net/confluence/display/IDP4/LDAPAuthnConfiguration</a><br /><br />-peter</div>
</blockquote>
</body></html>