NativeSP - exporting full SAML assertion to protected application?
Cantor, Scott
cantor.2 at osu.edu
Wed Feb 22 21:38:34 GMT 2012
> Do you have a suggestion for an alternate method of integrating shib login
> with a myproxy service?
I don't know anything about myproxy. The crudesaml thing appears to be SASL in some way, and there are a couple of SAML mechanisms proposed for SASL, one that's web based for desktops and apparently has some implementations around, and mine, which is ECP-based and is being prototyped by NCSA to work out the kinks.
> We are already investigating the
> shib/oauth/myproxy package from NCSA, but introducing an oauth service
> layer is what makes the saml/pam module look clean by comparison.
I can't really follow that thing, which was the source of my comment. If I saw a sequence diagram, I might feel differently, I don't know what it's doing exactly. I've seen PAM things that are broken in terms of spec adherence. I don't know if that option is or not.
There's also Moonshot, of course, if you're open to non-SAML options.
-- Scott
More information about the users
mailing list