Kerberos SSO with fail over to login auth

Aaron Roots aaron.roots at deakin.edu.au
Fri Oct 28 05:34:18 BST 2011


Thank you to all that responded - there some really good information that
will help greatly. 

The javascript for auto submitting browsers that have been configured as
compatible - appears to be an attractive work around

I may be on the wrong track here - but as I understand the RFC4559 is a
description of SPNEGO using Kerberos with failover to NTLM written by
Microsoft for their Integrated Windows Auth designed for Windows 2000 IIS.

A decade later, behaviour that might be better from a Shibboleth point of
view would be Kerberos with failover to Shibboleth  web login. From
looking at the source code, we seem to be issuing the 401 - would it be
possible to fail without issuing the 401 and somehow let Shibboleth try
another login handler? Or am I missing something client browser side that
will cause this to break? Or the way Login Handlers work?

Either way - I think I still have a bit of reading to do.

Cheers
Aaron



More information about the users mailing list