shibboleth-dev - Re: [Shib-Dev] IdP-side authorization or other post-authn processing
Subject: Shibboleth Developers
List archive
- From: Jim Fox <>
- To: "" <>
- Subject: Re: [Shib-Dev] IdP-side authorization or other post-authn processing
- Date: Tue, 7 Sep 2010 20:09:30 -0700
In our case, RL Bob's case, the SP is not inclined to adapt to our needs. It is unconscionable that we would simply tell our users that this issue conforms neither to our dogma nor that of an intransigent provider. We needed a working solution. It was important that we do our pre-authorization whether or not a user has an existing session with the IdP. It is also important to note that while some of the situations might be handled with existing attributes, others required queries available only to c language applications. So we had some issues. Because we use Apache in front of the IdP, and because the SP in question uses GET authn requests, it is quite easy to intercept these requests, using mod_rewrite, and pre-process them with a separate application. In essence we are invoking an authn process whether or not a session exists. I am looking forward to v3 to see how this functionality might be implemented natively. Jim |
- [Shib-Dev] IdP-side authorization or other post-authn processing, RL 'Bob' Morgan, 09/07/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Paul Hethmon, 09/07/2010
- RE: [Shib-Dev] IdP-side authorization or other post-authn processing, Peter Williams, 09/08/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Chad La Joie, 09/07/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Andrew Petro, 09/07/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Jim Fox, 09/07/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, RL 'Bob' Morgan, 09/08/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Jim Fox, 09/07/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Bradley Schwoerer, 09/08/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, RL 'Bob' Morgan, 09/08/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Bradley Schwoerer, 09/08/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, RL 'Bob' Morgan, 09/08/2010
- RE: [Shib-Dev] IdP-side authorization or other post-authn processing, Jones, Mark B, 09/08/2010
- Re: [Shib-Dev] IdP-side authorization or other post-authn processing, Paul Hethmon, 09/07/2010
Archive powered by MHonArc 2.6.16.