Kerberos SSO with fail over to login auth
Aaron Roots
aaron.roots at deakin.edu.au
Fri Oct 28 05:34:18 BST 2011
Thank you to all that responded - there some really good information that
will help greatly.
The javascript for auto submitting browsers that have been configured as
compatible - appears to be an attractive work around
I may be on the wrong track here - but as I understand the RFC4559 is a
description of SPNEGO using Kerberos with failover to NTLM written by
Microsoft for their Integrated Windows Auth designed for Windows 2000 IIS.
A decade later, behaviour that might be better from a Shibboleth point of
view would be Kerberos with failover to Shibboleth web login. From
looking at the source code, we seem to be issuing the 401 - would it be
possible to fail without issuing the 401 and somehow let Shibboleth try
another login handler? Or am I missing something client browser side that
will cause this to break? Or the way Login Handlers work?
Either way - I think I still have a bit of reading to do.
Cheers
Aaron
More information about the users
mailing list