Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The federated resource is: DOGS https://sp24-test.garr.it/i...dogs-101.html (Access protected by SAML SSO authentication)

The not federated resource is: CATS https://sp24-test.garr.it/i... (cats-101.html (Access forbidden, access permitted only through the IP of the proxyauthorised  IPs)

 

  1. Login to EXproxy EZproxy portal with your federated ID:
    1. choose your IdP (if not listed, ask to idem-help@garr.it to add your IdP to IDEM test federation for the purpose of this test)
    2. login with your home organisation credentials
  2. Choose the Federated Resource Dogs 101 (redirection to SSO) (note the URL http://ezproxy.fi.infn.it/login?url=Choose FR https://sp24-test.garr.it/idogs-101.html )
    1. after click,
    ...
    1. note the URL on the address bar of the browser https://sp24-test.garr.it/dogs-101.html . Your SAML SSO session is active and the paxe isn't proxed.
  3. Choose the Not Federated Resource Cats 101 (via proxy) (note the URL http://ezproxy.fi.infn.it/login?url=Choose NFR https://sp24-test.garr.it/icats-101.html )
    1. after click,
    ...
    1. note the URL on the address bar of the browserbrowser https://sp24-test-garr-it.ezproxy.fi.infn.it/cats-101.html . You are permitted to access thanks to the rewriting rule of the proxy.

 

Scenario B] NON-FEDERATED USER

...

  1. A user use only one unified method of authentication to access both federated and not federated resources
  2. For each resource the Library logs the access in a unified way. If a Resource is federated, only federated access will be allowed, and  IP based auth wont be permitted anymore. If a Resource is not federated, the user gets the access via IP address auth, and the proxy will log the access o that resource in this way.

 

DOGS https://sp24-test.garr.it/dogs-101.html