<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p><br>
</p>
<p>Thanks Brent. I will evaluate the Shibboleth SP.</p>
<p>A related question - is there a tutorial somewhere for generating
SP metadata? Is there some way to automate it, or does it require
manually building an XML document in code?</p>
<p><br>
</p>
<br>
<div class="moz-cite-prefix">On 09/27/2017 07:35 PM, Brent Putman
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:39fd63cf-4bae-338f-2696-c65dadac3b99@georgetown.edu">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<p><br>
</p>
<br>
<div class="moz-cite-prefix">On 9/26/17 12:15 PM, Jeff Ramin
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:07c387dd-1c00-23fc-aa80-9515a5a77bcf@singlewire.com">
<br>
I'm attempting to modify an existing application (via the use of
opensaml 3.0) to support SSO/SLO. The existing app will be a
service provider. <br>
<br>
</blockquote>
<br>
I will channel Scott and say that you really ought to do yourself
a favor and at least consider using a pre-existing SAML SP
implementation, if possible. Doing an SP properly is a *lot* of
work and requires a great deal of subject matter domain
expertise. Many implementations that one sees out there done by
primarily application developers with little to no specific SAML
expertise turn out to be absolutely horrible - and often broken in
a security vulnerability sense. I'm not saying that's necessarily
you... but presumably everybody thinks they are going to do it
right when they start....<br>
<br>
If you can front-end (reverse proxy) your Java app/container with
a web server like Apache httpd or IIS (a few other more esoteric
options exist, although maybe not applicable to Java apps), then
you might consider using the Shibboleth SP. (For what it's worth,
I'm the OpenSAML Java lead and that is what I do for my own Java
web applications in my local university non-Shibboleth project
work). If not, there are possibly a few other options for Java,
like Spring Security SAML (although I understand it's pretty
out-of-date at the moment).<br>
<br>
<blockquote type="cite"
cite="mid:07c387dd-1c00-23fc-aa80-9515a5a77bcf@singlewire.com">My
question - which package(s) in the opensaml library can be used
to consume/process IDP metadata? <br>
</blockquote>
<br>
Well, most/all the higher-level components which literally
directly parse metadata and produce a Java XMLObject model from
it, and allow resolution of EntityDescriptor(s) based on various
criteria, are under org.opensaml.saml.metadata, in Maven modules
opensaml-saml-api and opensaml-saml-impl. In particular I'm
talking about the various MetadataResolver implementations. The
object model classes themselves are under
org.opensaml.saml.saml2.metadata in the same modules.<br>
<br>
However, there are probably many other packages and classes which
are used more indirectly in the processing of metadata, and the
features/functionality derived from or dependent on it. Too many
for me to easily enumerate. OpenSAML and Shibboleth IdP pretty
much assume the use of SAML metadata everywhere, so it's pretty
ubiquitous throughout the library. You'd have to ask a more
specific question. <br>
<br>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Jeff Ramin
Software Engineer
Singlewire Software
1002 Deming Way
Madison, WI 53717
Phone Direct - 608.661.1172
<a class="moz-txt-link-abbreviated" href="http://www.singlewire.com">www.singlewire.com</a>
</pre>
</body>
</html>