NativeSP - exporting full SAML assertion to protected application?

Scott Koranda skoranda at gmail.com
Wed Feb 22 21:59:49 GMT 2012


>    On Feb 22, 2012 11:56 AM, "Cantor, Scott" <[1]cantor.2 at osu.edu> wrote:
>    >
>    [2]https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPAssertionExport
> 
>    � Excellent, thanks!
> 
>    > We probably have different definitions of "clean".
>    >
> 
>    ��� I admit, in this context, clean is a relative term.
> 
>    ��� Do you have a suggestion for an alternate method of integrating shib
>    login with a myproxy service? We are already investigating the
>    shib/oauth/myproxy package from NCSA, but introducing an oauth service
>    layer is what makes the saml/pam module look clean by comparison.
> 

Hi,

I do not understand your goals but perhaps the CILogon service
is of interest?

http://www.cilogon.org/

The CI Logon SP supports the ECP protocol. We will be
leveraging that to do

Kerberos -> IdP -> SAML -> X.509

(that's just a sketch not an architecture diagram...)

Scott K


More information about the users mailing list