Skip to Content.
Sympa Menu

inc-librsvcs - Re: [inc-librsvcs] Authentication plus authorization in EZproxy

Subject: InCommon Library Services

List archive

Re: [inc-librsvcs] Authentication plus authorization in EZproxy


Chronological Thread 
  • From: Rich Wenger <>
  • To:
  • Cc: "Paul B. Hill" <>, David Kennedy <>, inc-librsvcs <>
  • Subject: Re: [inc-librsvcs] Authentication plus authorization in EZproxy
  • Date: Fri, 03 Apr 2009 10:06:48 -0400

wrote:

Could a custom dataconnector in the IdP retrieve this info from the ROLES DB, and then send it along as an attribute?

I believe the IdP (perhaps only the version in subversion, and about to be released?) contains a SOAP client.
It is an interesting policy question whether or not this sort of provisioning belongs with the IdP. I have my
doubts, but am interested in hearing other views. It blurs the distinction between authentication and authorization,
a distinction that many IT departments have established with considerable effort.

-Rich



Archive powered by MHonArc 2.6.16.

Top of Page