RE: mod_auth_saml and certificates

Beaman, Thomas J. (ARC-IO)[PEROT SYSTEMS] wrote:
> Bleh, I forgot about the various sandboxing/chrooting I was doing to the
> system from Apache.  Once I took this into account it's working just fine
> - as far as I can tell :).
> As for the IdP, I'm not entirely sure since I didn't set it up - might be
> the SUN One IdP or it could be a completely different beast.
> Attached is a trick I used to compile apachezxid for a non-standard apache
> installation on OS-X (x86), maybe it'll come in handy for somebody else.
> I figured that one out a while back and Googling for a long time.

I realize that you explicitly claim that your setup is "non-standard",
but if you possibly can generalize the fix so it could appear in
the TARGET=macosx section of the Makefile, I will include your
patch in the distribution.

> I've now updated to 0.38 and I believe the changelog states that the
> Attribute Broker has been implemented, correct?  Is there some updated
> documentation available that describes how to configure this on the ZXID
> side?

The Attribute Broker, PEP (XACML Policy Enforcement Point) and
local PDP features are extensively described in
zxid-conf.pd (http://zxid.org/html/zxid-conf.html)
section 4 ZXID Attribute Broker (ZXAB): the relevant config
directives are NEED, WANT, ATTRSRC (still a stub), INMAP, and OUTMAP;
and in section 5 ZXID XACML PEP: the relevant config directives
LOCALPDP_IDPNID_DENY, PEPMAP, and PDP_URL. You may want to study
the zxidconf.h for default values of NEED, WANT, and PEPMAP.

In order to not oversell the current state of the art, I must
note that the attribute "broker" is only able to get and translate (map)
the attributes from the SSO SAML Assertion (A7N). Plan is to add
local filesystem based attribute provider (database or LDAP based
local providers would be nice, contributions welcome) and some form
of web service based attribute query (ID-DAP or SAML Attribute
Requester - feedback about which is more demanded is welcome).


