Back Channel Communications in shibboleth.
Eddie Harari
eddie.harari at gmail.com
Tue Jun 5 12:20:40 BST 2012
Hi and thanks a lot for the quick and helpful replies.
I understand that what I am looking for is saml2 delegated
authentication support.
I was looking at the resources you have sent me and also searched for
some more materials on "HOW TO" ...
I understand that this is part of ECP profile support and that this is
now part of the shibboleth core.
I would like to know if there is a code sample (PHP or so ) for the
ECP delegated authetication and also if ECP delegated authenticatin is
supported in the IDP or i should install some kind of a module into
the IDP to support ECP delegated authentication.
( I could not understand that from the documentation ).
thanks ,
Eddie.
On 6/4/12, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 6/4/12 6:36 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>>* Eddie Harari <eddie.harari at gmail.com> [2012-06-04 12:27]:
>>> can an SP take the SAML2 token comming from the user agent via IDP
>>> and use it as an authentication proof to a different SP.
>>> Is this a possible scenario ?
>>
>>See https://wiki.oasis-open.org/security/SAML2DelegationCondition for
>>examples and terminology. There might also be material at
>>https://spaces.internet2.edu/display/ShibuPortal/Home but I don't know
>>the status of that,
>
> That is wordy and overly technical rather than deployer focused, but it's
> still accurate. That's the basis of the delegation work we did along with
> Unicon and remains the project's implemented solution for what was asked
> about.
>
> And no, you can't generally take the original token and do that, SAML
> doesn't allow it. You have to exchange it for a new token at the IdP.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
More information about the users
mailing list