<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
You can configure the context-check intercept and activate context checking only for the SPs that require it.</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509927/ContextCheckInterceptConfiguration" data-outlook-id="e7b4ac43-70db-4d3b-999f-468119c65231">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509927/ContextCheckInterceptConfiguration</a></div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="mail-editor-reference-message-container">
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"></div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="text-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; border-style: solid none none; border-color: rgb(181, 196, 223) currentcolor currentcolor; font-family: Aptos; font-size: 12pt; color: black;">
<b>From: </b>users <users-bounces@shibboleth.net> on behalf of Jehan PROCACCIA <jehan.procaccia@tem-tsp.eu><br>
<b>Date: </b>Monday, December 8, 2025 at 3:05 AM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Subject: </b>Re: how to deny acces to a SP based on attribute value<br>
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hello</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I don't use MFA for now, but if that's a way to make it run as expected, I'll go in that direction .</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Indeed , I am not convince that replying-party config could be the right way to do that ?</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I am surprise though that this kind of access control to a Service Provider based on an attribute value is not that much documented</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I've seen it in <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509766/ActivationConditions" originalsrc="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509766/ActivationConditions" data-outlook-id="c968a3dc-f66b-4937-a1da-f1e89219a29b">
https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509766/ActivationConditions</a></div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
chapter => Attribute Checking<br>
but it's not clear where to apply it, and how to corrolate that to a specific SP for denied access</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
If there a simple way to do that " deny acces to a SP based on attribute value" ? , I take it in the first place</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
but I would also like to see your sample config to acheive the whole process, as you seem to have done it compeltly even with a messaged returned to users who are rejected !</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks for you help .</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
jehan</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
<br>
</div>
<hr>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>De: </b>"db--- via users" <users@shibboleth.net><br>
<b>À: </b>"Shib Users" <users@shibboleth.net><br>
<b>Cc: </b>"db@alaska.edu" <dabantz@alaska.edu>, "users" <users@shibboleth.net><br>
<b>Envoyé: </b>Dimanche 7 Décembre 2025 21:38:40<br>
<b>Objet: </b>Re: how to deny acces to a SP based on attribute value</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We do something similar to deny sign-ins to specific SPs if eduPersonAffiliation is only affiliate - not member/student/faculty/staff. But relying-party is not AFAIK capable of stopping sign in as you want. We create an attribute in resolver to flag stop (based
on ePA and entityID of service), then use script in mfa config to set a nextFlow if triggered, and a vm that displays message to user. Details on request.</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
David.Bantz@Alaska.edu</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<blockquote>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
On Dec 7, 2025, at 11:09, jehan.procaccia@tem-tsp.eu wrote:<br>
<br>
</div>
</blockquote>
<blockquote>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">Hello</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">I want to deny access to a specific SP to users whose ldap resolved attribute contains specific
values and allow for other values</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">in my case specific SP is entityID
<i><a href="https://sp.im.fr/sp" target="_blank" rel="nofollow noopener noreferrer" originalsrc="https://sp.im.fr/sp" data-outlook-id="f89bb651-7e18-450b-9d11-881d9f5ac3f6" style="margin-top: 0px; margin-bottom: 0px;">https://sp.im.fr/sp</a></i> and attribute
is <i>eduPersonPrimaryAffiliation</i> which should be = to "staff" or "employee" to be allowed access, if a value of "student" is resolved (or others as affiliate,member ...) , access to the SP should be denied .</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">So I have created a RelyingPartyOverrides in relaying-party.xml with activationCondition based
on the value of the attribute for that specific relyingParty, the code is loaded (IDP starts well, it took me a while with lots of errors ...) , now users can connect , but also users with eduPersonPrimaryAffiliation that are different from staff or employee
in my case [1] :-(</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">I guess that my IdP (v5.1.6) does not deny access when my relying-party activationCondition
evaluates to false, and then it might falls back to the default relying-party config with the default SAML2 SSO profile which is not restricted !?</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">can you help me buiding an operational configuration that allow access to that specific SP only
for users whose <i>eduPersonPrimaryAffiliation = staff or employee </i>?</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">is relying-party.xml the right place to do that, or access-control.xml file should be involved
?</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">regard</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">jehan</span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0);"><i> <util:list id="</i><b><i>shibboleth.RelyingPartyOverrides</i></b><i>"></i></span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0);"><i> <bean id="MistralAI" parent="RelyingPartyByName"
</i><b><i>c:relyingPartyIds="#{{'<a href="https://sp.im.fr/sp" target="_blank" rel="nofollow noopener noreferrer" originalsrc="https://sp.im.fr/sp" data-outlook-id="ab493ce8-0dd5-4eea-878f-0c38ec3bd4ca" style="margin-top: 0px; margin-bottom: 0px;">https://sp.im.fr/sp</a>'}}"</i></b><i>><br>
<br>
<property name="</i><b><i>activationCondition</i></b><i>"><br>
<bean parent="</i><b><i>shibboleth.Conditions.SimpleAttribute</i></b><i>"><br>
<property name="attributeValueMap"><br>
<map><br>
<entry key="</i><b><i>eduPersonPrimaryAffiliation</i></b><i>"><br>
<list><br>
<value></i><b><i>staff</i></b><i></value> </i></span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0);"><i> <value>employee</value></i></span></p>
<p dir="ltr" class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: arial, helvetica, sans-serif; font-size: 13px; color: rgb(0, 0, 0);"><i> </list><br>
</entry><br>
</map><br>
</property><br>
</bean><br>
</property><br>
<br>
<property name="profileConfigurations"><br>
<list><br>
<bean parent="SAML2.SSO"<br>
p:encryptAssertions="false"<br>
p:checkAddress="false" /><br>
</list><br>
</property><br>
<br>
</bean></i><br>
</span><span style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"><br>
</span></p>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
--<br>
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div>
</blockquote>
<div class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
--<br>
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div>
<div dir="ltr" class="ms-outlook-mobile-reference-message skipProofing" style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
</div>
</body>
</html>