delegated authentication without specifying SPs in advance

Yana Panchenko yana_panchenko at yahoo.com
Mon Aug 22 15:12:01 BST 2011


Hi,

I am new to Shibboleth and to security mechanisms in general, I've been reading (at https://spaces.internet2.edu/display/ShibuPortal/Configuring+Shibboleth+Delegation+for+a+Portal) that Shibboleth has support for delegated authentication. My question is: is it possible to have delegation where a SP is allowed to delegate to any other SP without specifying SP entity id in advance?

In our case: A web application (SP1), protected by Shibboleth, is accessed by a user. The user is authenticated by IdP. Then, on behalf of the user, the application SP1 may call a bunch of other SPs (RESTfull services) in other organisations that are also protected by Shibboleth and are within the federation. 
As far as understood, for this to work, at IdP side it must be explicitely configured which SPs are allowed to delegate to which SPs. But we want our SP1 to call any other service without restrictions on the entities called, because we may not know in advance all participating SPs from other organizations. Is it possible with Shibboleth? Or, if not, maybe you could point to a possible solution?

Thanks for any help,
Yana
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20110822/69712ca8/attachment.html 


More information about the users mailing list