Shib and ADFS 2.0 Help

Cantor, Scott cantor.2 at osu.edu
Fri Jun 29 17:50:20 BST 2012


On 6/29/12 11:38 AM, "Michael W. Brogan" <mbrogan at u.washington.edu> wrote:

>We've messed around and had some success in getting a .Net application to
>authenticate against our Shib IdP without all the ADFS infrastructure in
>the middle. To do that our developer used the "WIF Extension for the SAML
>2 Protocol CTP." See
>http://blogs.msdn.com/b/card/archive/2011/05/16/announcing-the-wif-extensi
>on-for-saml-2-0-protocol-community-technology-preview.aspx for a blog
>post and download link.

Yes, I would think that's the best choice, assuming it's going to be
released.

>I really hope I don't have to setup an entire ADFS infrastructure just
>for one application that can't talk native Shib.....

ADFS is a gateway. It doesn't offer a pure SAML agent, it uses an IIS
agent that does WS-Federation, and then you translate between the ADFS
server and the agent to do SAML.

I don't know if you can do ADFS install with no AD service, but you
definitely can't use it without the full ADFS server.

-- Scott



More information about the users mailing list