NativeSP - exporting full SAML assertion to protected application?

Jim Basney jbasney at illinois.edu
Thu Feb 23 13:04:20 GMT 2012


On 2/23/12 2:57 AM, Stephen Chan wrote:
> I had been hoping that the oauth for myproxy solution
> would be a relatively "drop in" solution. However it introduces an oauth service
> that either prompts the user for username/password (thus defeating web SSO)
> or else is trusted to impersonate anybody to the MyProxy server (which is
> worrisome).

In other words, our approach is a web front-end for MyProxy that uses
Shibboleth/SAML for authentication and OAuth for delegation. The MyProxy
server trusts mod_shib on the web front-end to authenticate users,
rather than having MyProxy itself implement SAML.

-Jim


More information about the users mailing list