6e0acc8997
Added encrypted assertions with self contained namespaces. Added possibility to add two assertions. One encrypted with all the attributes and a second one that is not encrypted and contains nameid and authentication statement.
43 lines
1.0 KiB
INI
43 lines
1.0 KiB
INI
[plugin:auth_tkt]
|
|
# identification
|
|
use = repoze.who.plugins.auth_tkt:make_plugin
|
|
secret = kasamark
|
|
cookie_name = pysaml2
|
|
secure = False
|
|
include_ip = True
|
|
timeout = 3600
|
|
reissue_time = 3000
|
|
|
|
# IDENTIFIER
|
|
# @param :
|
|
# - rememberer_name : name of the plugin for remembering (delegate)
|
|
[plugin:saml2auth]
|
|
use = s2repoze.plugins.sp:make_plugin
|
|
saml_conf = sp_conf
|
|
remember_name = auth_tkt
|
|
sid_store = outstanding
|
|
idp_query_param = IdPEntityId
|
|
#discovery = http://130.239.201.5/role/idp.ds
|
|
|
|
[general]
|
|
request_classifier = s2repoze.plugins.challenge_decider:my_request_classifier
|
|
challenge_decider = repoze.who.classifiers:default_challenge_decider
|
|
remote_user_key = REMOTE_USER
|
|
|
|
[identifiers]
|
|
# plugin_name;classifier_name:.. or just plugin_name (good for any)
|
|
plugins =
|
|
saml2auth
|
|
auth_tkt
|
|
|
|
[authenticators]
|
|
# plugin_name;classifier_name.. or just plugin_name (good for any)
|
|
plugins = saml2auth
|
|
|
|
[challengers]
|
|
# plugin_name;classifier_name:.. or just plugin_name (good for any)
|
|
plugins = saml2auth
|
|
|
|
[mdproviders]
|
|
plugins = saml2auth
|