WS-Federation resource provider relationship with our IdP
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 28 14:26:53 EDT 2014
On 3/28/14, 2:05 PM, "Brian Reindel" <giantjamsandwich at gmail.com> wrote:
>Thanks Scott, this is definitely why I wanted to ask because I don't
>appear to be thinking about it right. So I guess I will focus in on
>this:
>
>>> ADFS supports SAML 2.0, so the best choice is to use that.
>
>Are you saying the client would use ADFS to connect to our Shibboleth
>IdP using SAML 2 assertions?
Using the SAML 2.0 Browser SSO profile, not just assertions.
It speaks the same profile Shibboleth does. It is, as commercial options
go, among the better ones (this is a low bar).
You will likely have to create some dedicated attribute configuration to
supply data to them in the way it prefers if you want to insulate them
from having to make a lot of changes on their end, or you can stick to
vanilla and force them to accomodate the standard attribute names and
approaches Shibboleth follows. Much of the documentation from MS is around
some of that, and the rest is primarily about metadata issues.
-- Scott
More information about the dev
mailing list