Forum Discussion
Michael_Falkenr
Jan 26, 2005Historic F5 Account
Pulling Group Attribute via Authentication Rules
I've had several prospects ask for the ability for BIGIP not only to authenticate against an external device (AD, Radius, LDAP) but also have the ability to extract/store group attributes so that we c...
Loc_Pham_101863
Jan 26, 2005Historic F5 Account
Here's the response from one of our developers working in the auth area:
1) We do not authenticate to NIS+.
2) There are no currently scheduled releases with enhanced auth rules that have the ability to redirect to an error page. That said, a simple modification to the rule should allow this to happen quite easily. I am currently working on some auth enhancements, and I'll see if I can't figure out how to get that into an auth option. I think it makes the most sense to make a redirect page part of the auth profile. If the rule can get arguments from the profile, then we can write one rule that always redirects correctly.
3) Big-IP cannot currently pass information up from the bottom of the PAM stack. i.e. once a user is authenticated, no additional information (such as group affiliation, user attributes, etc.) is passed up to the BIG-IP to be used for authorization. However, I have written up an example of what I call "selective authentication". Using this method, you can authenticate users who are in a chosen group, have a certain attribute, etc.
I'm not sure if that will solve the problem this user has. However, again, we have a plan to do this in a future release.
Regards,
Loc
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects