Kerberos SSO with fail over to login auth
Nick Duan
nduan at verizon.net
Thu Oct 27 05:27:41 BST 2011
Shouldn't Shibboleth be the "Internet replacement" of Kerberos? Why do you
want to make these two play together? Each serves different purpose in
different environment. What would be the use case for integrating Kerberos
with Shibboleth?
Thanks!
ND
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On
Behalf Of Aaron Roots
Sent: Wednesday, October 26, 2011 6:17 PM
To: Shib Users
Subject: Kerberos SSO with fail over to login auth
Hi all,
Just looking if anyone has successfully setup Kerberos Auth to the
Shibboleth IdP that occurs automatically - but if there is no ticket or
the ticket is not valid then it fails back to the login web page.
I am just about to start looking into achieving this - from the
preliminary reading I have done so far I have seen the following:
* Fully Kerberos with no fail over as all users are using an SOE
* Choice of login type on the login web page
* Using Apache - but fails over to a basic auth box instead of a login
screen
* Wanting the above scenario - but not having achieved it yet
I am hoping somebody may have had some success that I haven't come across
yet and have any advice they could share. If not that's all good - just
means I'll probably be very busy for a few weeks :)
Cheers heaps,
Aaron
--
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
More information about the users
mailing list