Skip to content

SAML Auth via SU IdP #16

@mjmaurer

Description

@mjmaurer

Resources:

Steps:

  • Create workgroup for geomatch staff (already request geomatch stem)
  • Will need to add GeoMatch to SPDB
  • If AWS Cognito ALB SP supports signing requests then we don't have to add callback URLs (assertion consumer service). It doesn't mention how to provide public key to Stanford IdP.
  • Need to map eduPersonEntitlement (see here) and then authorize based on that
  • Cognito might not be able to do authz because it doesn't support challenges for federated authn. But, we can instead just return an error in post-authn lambda. Errors will cause authn to fail

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions