NativeSP - exporting full SAML assertion to protected application?

Cantor, Scott cantor.2 at osu.edu
Wed Feb 22 21:38:34 GMT 2012


>     Do you have a suggestion for an alternate method of integrating shib login
> with a myproxy service?

I don't know anything about myproxy. The crudesaml thing appears to be SASL in some way, and there are a couple of SAML mechanisms proposed for SASL, one that's web based for desktops and apparently has some implementations around, and mine, which is ECP-based and is being prototyped by NCSA to work out the kinks.

> We are already investigating the
> shib/oauth/myproxy package from NCSA, but introducing an oauth service
> layer is what makes the saml/pam module look clean by comparison.

I can't really follow that thing, which was the source of my comment. If I saw a sequence diagram, I might feel differently, I don't know what it's doing exactly. I've seen PAM things that are broken in terms of spec adherence. I don't know if that option is or not.

There's also Moonshot, of course, if you're open to non-SAML options.

-- Scott



More information about the users mailing list