So, as you've all probably heard or read, Cosign was meant for
Authentication only, and we've tried to isolate that as much as
possible. But while Authentication is necessary, it if often not so
useful without Authorization. And to that end, the cosign team has gone
and appropriated mod_authz_ldap ( http://authzldap.othello.ch/ ) for
LDAP group and role authorization. And I'm pleased to say it even
works!
From the download page on weblogin.org, you can now find:
This is a how-to on building and configuring mod_authz_ldap to work
with cosign ( or any other AuthN that populates REMOTE_USER ). These
notes include a small patch that we have submitted to the author and
will theoretically be included in the next release. So, if you're an
early adopter, you're gonna need to patch for now. :)
Feel free to send questions or comments to cosign-discuss list!