RFC extensions to Shibboleth
Andrea Biancini
andrea.biancini at mib.infn.it
Tue Sep 4 10:09:22 EDT 2012
Leif, I got your point.
The username+password for linux authentication was our point of start
because usually Linux systems authenticate users this way.
However I share with you your concern about the philosophy and general
architecture of Shibbolet.
One modification we are trying to do to our code, is that of replacing the
Basic Auth mechanism with the ECP profile (used in different other projects
in this area on Shibboleth).
Would you think that using SAML ECP profile we would be able to obtain our
goal without a significant modification of Shibboleth abstraction
architecture?
On Tue, Sep 4, 2012 at 2:53 PM, Leif Johansson <leifj at sunet.se> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
> > We would really appreciate feedback on the work done in order to
> > understand with the community if the direction taken is good or if
> > some review may be suggested. Thanks and regards,
>
> My problem is that this assumes that the IdP uses username & password.
>
> This is an increasingly invalid assumption, for instance as sites roll
> out ADFS2 which uses Negotiate instead of Basic.
>
> The point of SAML is to have an abstraction layer, so that relying
> parties could move beyond passwords.
>
> This breaks that abstraction layer.
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.11 (GNU/Linux)
> Comment: Using GnuPG with Mozilla - http://www.enigmail.net/
>
> iEYEARECAAYFAlBF+boACgkQ8Jx8FtbMZndtBACeKFfmFkYZJhBggKX/tho4nTR8
> hoUAn2GhY1DLuh8B0IwE3ICbOA/mGTiI
> =P5A8
> -----END PGP SIGNATURE-----
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20120904/8e631363/attachment.html
More information about the dev
mailing list