inc-librsvcs - Re: [inc-librsvcs] Authentication plus authorization in EZproxy
Subject: InCommon Library Services
List archive
- From:
- To: inc-librsvcs <>
- Subject: Re: [inc-librsvcs] Authentication plus authorization in EZproxy
- Date: Fri, 3 Apr 2009 11:00:51 -0400
At 10:06 AM -0400 4/3/09, Rich Wenger wrote:
wrote:
It is an interesting policy question whether or not this sort of provisioning belongs with the IdP. I have my
Could a custom dataconnector in the IdP retrieve this info from the ROLES DB, and then send it along as an attribute?
I believe the IdP (perhaps only the version in subversion, and about to be released?) contains a SOAP client.
doubts, but am interested in hearing other views. It blurs the distinction between authentication and authorization,
a distinction that many IT departments have established with considerable effort.
I'd argue, tho, that in this specific case MIT is NOT REALLY authorizing access. Yes, you're blocking some users. And you're allowing others thru. But, I *suspect* there are ways around your in place systems...
Ultimately, the vendor has to decide whether or not to let the user in. In this case, the vendor may be configured to ONLY accept requests from the IP address of your EZP server (rather than any address on the MIT network). That's their access control policy. And if I can figure out a way around it, then I'm into their service....
You're helping them.... and doing a good job of it. But, ultimately, it still their problem and responsibility....
- Authentication plus authorization in EZproxy, Rich Wenger, 04/02/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, David Kennedy, 04/02/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Paul B. Hill, 04/02/2009
- RE: [inc-librsvcs] Authentication plus authorization in EZproxy, Foster Zhang, 04/02/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Steven_Carmody, 04/03/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Rich Wenger, 04/03/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Tom Barton, 04/03/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Steven_Carmody, 04/03/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Rich Wenger, 04/03/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Rich Wenger, 04/03/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, Paul B. Hill, 04/02/2009
- Re: [inc-librsvcs] Authentication plus authorization in EZproxy, David Kennedy, 04/02/2009
Archive powered by MHonArc 2.6.16.