Using Sharepoint Credentials for Remote User Authentication

THIA Jean-Marie jean-marie.thia at upmc.fr
Fri Jul 20 16:34:31 EDT 2012


Bonnie,
I AM on vacation until Thursday. I will give a look at success factor then.
Jean Marie

Envoyé depuis un mobile
________________________________
De : Bonnie Jones
Envoyé : 18/07/2012 02:14
À : Shib Users
Objet : RE: Using Sharepoint Credentials for Remote User Authentication

Jean Marie,
Thank you for your reply.  I think I will need to stick with SharePoint as that is our begin point for all things related to compensation.  My service provider is Success Factors.

I found your document “Step-by-step Guide:  Federated Collaboration with Shibboleth 2.0 and SharePoint 2010 Technologies”.  Although we don’t use ADFS I thought it would give me some insight.  I know very little about SharePoint.  Based on your response I have been looking at creating an external content type.  I’m not sure how to launch that since I am just calling a url and passing the shire, target and providerid.  I can see where I can choose to  impersonate a unique user.

Is the external content type what you were thinking of or is there a different web part that you would recommend?

Bonnie

From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of THIA Jean-Marie
Sent: Friday, July 13, 2012 2:43 AM
To: Shib Users
Subject: RE: Using Sharepoint Credentials for Remote User Authentication

Hi Bonnie,

>From what I understand your service provider is Shibboleth enable, your users are authenticated on the network using AD and connect seamlessly to SharePoint.
And yours users should access the provider application without sign in.

Is the application accessed directly ? In this case you should rely on Kerberos as Shibboleth back end
Is the application exposed through a webpart ? You may impersonate to a unique user.

Jean Marie

Envoyé depuis un mobile
________________________________
De : Bonnie Jones
Envoyé : 13/07/2012 01:01
À : users at shibboleth.net<mailto:users at shibboleth.net>
Objet : Using Sharepoint Credentials for Remote User Authentication
Hello,
We have purchased a Performance Management package to replace one built in-house.  It is hosted externally.  I have a requirement for our users to connect without having to enter their username and password.  Since they have already logged into the network and again into our intranet Sharepoint site they have already been authenticated and should just be able to seamlessly access this application.

As a starting point I have installed Shibboleth IdP 2.3.6 on a Windows Server with Tomcat 6.0.  I am successfully connecting to my service provider using Idp Initiated SSO and UsernamePassword Auth handler connecting to Active Directory with LDAP.  The only attribute I need to pass is their userid.  I have a form on a jsp page that autosubmits with the parameters for Idp Initiated SSO.  Shibboleth is installed on a separate server from Sharepoint.

Now that I have that working I expected to use the remote user handler and somehow set the header information from Sharepoint.  I can pick up the userid with javascript from the sharepoint user context and am looking at ajax to set the header information.  The alternative is to use the IE Activex control to pick off the userid of the person logged into the workstation and forget about sharepoint but I am still not sure how to set the header information.

Has anyone had any experience with this?  If so can you point me in a direction or is there an alternative that still meets this requirement?

Thanks.
Bonnie
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120720/dd87ea9f/attachment-0001.html 


More information about the users mailing list