IdP session proxy

Russell Beall beall at usc.edu
Thu Oct 27 20:27:56 BST 2011


Hi,

I am in the interesting position of having to support VivanTech in their development of their Kuali KFS iPhone app.  This app is trying to access the main KFS servers, but because those servers are Shibbolized, the app needs a session.

To "work around" this, they developed a proxy server and the app communicates to the proxy, and the proxy creates a full web session with the server.  The proxy plugs in the username and password at the IdP.

I warned them long ago that following this route would lead to trouble and would be a bad idea, but by the time they talked to me they had invested so much that the train kept right on rolling, and they have had plenty of issues as expected.

My question is: are there other users who follow a proxy model, hopefully in a somewhat secure fashion?

Is this something that is a feasible workaround as long as all communications are encrypted?  (I have numerous considerations and see many potential security holes, but instead of listing them I'd rather hear what other people think about this).

I know that ECP might be preferable now, but it wasn't available when they were getting this going.

Thanks,
Russ.



More information about the users mailing list