delegated authentication without specifying SPs in advance
Yana Panchenko
yana_panchenko at yahoo.com
Mon Aug 22 15:12:01 BST 2011
Hi,
I am new to Shibboleth and to security mechanisms in general, I've been reading (at https://spaces.internet2.edu/display/ShibuPortal/Configuring+Shibboleth+Delegation+for+a+Portal) that Shibboleth has support for delegated authentication. My question is: is it possible to have delegation where a SP is allowed to delegate to any other SP without specifying SP entity id in advance?
In our case: A web application (SP1), protected by Shibboleth, is accessed by a user. The user is authenticated by IdP. Then, on behalf of the user, the application SP1 may call a bunch of other SPs (RESTfull services) in other organisations that are also protected by Shibboleth and are within the federation.
As far as understood, for this to work, at IdP side it must be explicitely configured which SPs are allowed to delegate to which SPs. But we want our SP1 to call any other service without restrictions on the entities called, because we may not know in advance all participating SPs from other organizations. Is it possible with Shibboleth? Or, if not, maybe you could point to a possible solution?
Thanks for any help,
Yana
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20110822/69712ca8/attachment.html
More information about the users
mailing list