<div dir="ltr">Hi Scott, <div><br></div><div>Thanks for your advice, I'm really not trying to reinvent the wheel, so if you have easier solutions, they are most welcome!</div><div><br></div><div>I'm not planning to implement SAML myself, rather I intent to re-use as much as possible from OpenSAML to implement WebSSO. Maybe I am misunderstanding things, as it is all kind of new to me. The security is handled by Wicket, I just need the authentication part.  </div><div><br></div><div>What would you suggest? I want the configuration as simple as possible, preferable without bringing in big libraries, and being able to do configuration in code as much as possible.  And I would like to understand what is happening, so in case something doesn't work, I might be able to fix it :)</div><div><br></div><div>-Rob</div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, May 24, 2017 at 3:35 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 5/24/17, 4:59 AM, "dev on behalf of Rob Audenaerde" <<a href="mailto:dev-bounces@shibboleth.net">dev-bounces@shibboleth.net</a> on behalf of <a href="mailto:rob.audenaerde@gmail.com">rob.audenaerde@gmail.com</a>> wrote:<br>
<br>
> My interest is to implement WebSSO in my own (Wicket) application, where we can:<br>
<br>
</span>Please, don't. Just use an existing SAML implememtation. You should not implement SAML inside any application. You shouldn't implement security of any kind inside a web application.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>