Shibb + Panopto + AD TokenGroups

Chuck Kimber chuck.kimber at usu.edu
Tue Mar 20 21:04:06 GMT 2012


We're working on implementing Panopto to record courses and hoping we
can pull off authentication with Shibboleth.  Out of the box Panopto
supports ADFS, which is SAML 2, of course.  Panopto doesn't officially
support anything except ADFS, but we'd like to avoid confusing users
by shipping them to yet another SSO.

So my first question would be, has anyone out there successfully used
Shibboleth to authenticate Panopto?  The google searches and reading
I've done seem thin...  If someone has pulled it off, they don't seem
to be talking about it.  I would welcome any tips, examples, insight
and warnings you might have.

I have been experimenting and playing with it, based on their ADFS
config (http://support.panopto.com/focus-4-articles/24-activedirectory/399-hosted-panopto-federated-authentication)
and have stored their metadata, configured basic filters etc, but
there is one AD attribute they want that seems problematic.  The AD
attribute "tokenGroups".  I am unable to pull this attribute
successfully with any tool, even powershell with the ActiveDirectory
module, to examine it.
http://msdn.microsoft.com/en-us/library/windows/desktop/ms680275%28v=vs.85%29.aspx
 From what I've uncovered so far this attribute seems to be some kind
of conglomerate value that has to then be broken down into SID's and
enumerated.  Even if I can get my hands on that attribute, I'm not
sure how I would pull off the enumeration of it in Shibboleth.  I'm
hoping someone out there has cracked this nut before and can show me
how.  Any ideas?

Chuck
Utah State University


More information about the users mailing list