Social identity providers: supporting via gateway and supporting via native Shib SP v2.5 "back door"
Russell Beall
beall at usc.edu
Mon Jul 30 18:54:22 EDT 2012
I have a project going which relates to this and brings social logins to service providers. If you are not referring to a specific codebase for your gateway version, then this would be an alternative gateway.
This one uses a custom coded oAuth gateway in a servlet at the IdP. An SP only needs a simple setting to request the custom authentication context to use it.
Additional attributes may be bound to the principal in our institutional LDAP service using our guest registration and groups management services, and these attributes will also be delivered (such as entitlements granting additional privileges). The identity of both the oAuth provider as well as the Shibboleth IdP can be sent as attributes to the SP (this was a requirement I see from an earlier e-mail from Keith on this topic).
This approach makes it extremely simple on the service provider side so that departments with limited IT staff could still use it with ease. On-campus departments are pretty familiar with setting up an SP at this point, but would have a difficult time integrating with oAuth independently.
I'll be showing this in a session at the next I2 in case anyone wants to take a look.
If this is of interest to your project, I will probably be rolling this out into our test IdP service in the not-too-distant future, and others wishing to try it out could connect there when it is ready.
Regards,
Russ.
==============================
Russell Beall
Programmer Analyst IV
Enterprise Identity Management
University of Southern California
beall at usc.edu
==============================
On Jul 30, 2012, at 9:35 AM, Keith Hazelton wrote:
> The MACE-Social Identity Working Group (https://spaces.internet2.edu/display/socialid/Home) is beginning trials with two approaches to adding support for social identity providers to our SAML SPs. One is a social2SAML gateway, and Paul Caskey of UT System is standing up a trial gateway. The other is leveraging functionality new to the Shib SP in version 2.5 (release candidate now available) that allows authN plugins that would facilitate adding social IdPs to an SPs supported modes of authentication. See
> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPBackDoor
>
> I am hoping people who wish to try the Shib SP "back door" approach to integrating Social IdPs will respond to this email with a statement of interest. As of this moment, Chris Hubing at the University of Pennsylvania and Keith Hazelton (UW-Madison and Project Bamboo) are committed to trials of such Shib SP-based solutions. Chris has an implementation configured and working and intends to document his approach once he irons out a couple issues.
>
> Looking forward to hearing from interested parties, --Keith Hazelton
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120730/5faee0af/attachment.html
More information about the users
mailing list