WS-Federation resource provider relationship with our IdP

Brian Reindel giantjamsandwich at gmail.com
Fri Mar 28 10:27:38 EDT 2014


We have an existing enterprise SSO solution using Shibboleth (one IdP
and several SPs). We have a new client, and they use ADFS in house.
They want to authenticate into our product using WS-Federation, but
I'm having trouble understanding the relationship of the various
technologies involved.

As I understand it in Shibboleth terms at a high level, they have an
SP that we would trust as a relying party through the appropriate IdP
configuration as usual. They would authenticate, and upon return to
their system they would simply redirect over to our SP (product) that
would then communicate with the IdP and establish trust based upon the
previous authentication. Does that sound correct at a very high level?
We currently have two login handlers configured (RemoteUser and
ExternalAuthn), and I'm also curious how those handlers fit into the
picture.

I really want to know what is the appropriate flow in the given
scenario. Other than some additional configuration caveats for our IdP
to support WS-Federation I don't see any glaring holes. The existing
documentation I'm reviewing is as follows:

http://msdn.microsoft.com/en-us/library/bb498017.aspx

https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPADFS

http://technet.microsoft.com/en-us/library/gg317734(v=ws.10).aspx

Is there other documentation I should be reviewing?

Thanks,
Brian


More information about the dev mailing list