[shib_auth] unauthorized user geting authenticated

cesar ceballos cceballos45 at yahoo.com
Thu Nov 13 18:35:10 CET 2014


Hi,

I am using Drupal 6 for website using SSO authentication, so for log into the site a user has to accomplish:

1- Benig recognized by the SSO

2-
 Being part of those users from the general SSO that is also authorized 
to log into the site, according to the site's shibboleth group rules.

Now I am facing the following problem:

If
 a valid user for SSO that does not belong to those allowed to log into 
my website tries to access it via https, it gets correctly refused. But 
then after receving the authorization fail, if the user changes to http 
access, it acceess the
 site being authenticatd (registered as "authenticathed user").

Any help?

Thanks in advance,

César.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://listserv.niif.hu/pipermail/shib_auth/attachments/20141113/fbf1023e/attachment.html>


More information about the shib_auth mailing list