Shibb + Panopto + AD TokenGroups

Randy Wiemer wiemerr at hotmail.com
Tue Mar 20 21:52:26 GMT 2012


> Out of the box Panopto supports ADFS, which is SAML 2,> The statment that ADFS is SAML 2 is not really relevant in this case. The metadata they publish reveals they are using WS-* protocols and not SAML.  Their application is probably using WIF which means they don't really even need ADFS on their side. https://panoptoacs.accesscontrol.windows.net/FederationMetadata/2007-06/FederationMetadata.xml  You can use an ADFSv2 server on your side to perform what amounts to a protocol translation from the SAMLv2 performed by your Shibboleth IdP to WS-Federation that the service provider expects.  Your users would not have to see any of this if you control the URLs they'd use to reach the service provider.
Randy Oxford Computer Group
 > From: chuck.kimber at usu.edu
> Date: Tue, 20 Mar 2012 15:04:06 -0600
> Subject: Shibb + Panopto + AD TokenGroups
> To: users at shibboleth.net
> 
> We're working on implementing Panopto to record courses and hoping we
> can pull off authentication with Shibboleth.  Out of the box Panopto
> supports ADFS, which is SAML 2, of course.  Panopto doesn't officially
> support anything except ADFS, but we'd like to avoid confusing users
> by shipping them to yet another SSO.
> 
> So my first question would be, has anyone out there successfully used
> Shibboleth to authenticate Panopto?  The google searches and reading
> I've done seem thin...  If someone has pulled it off, they don't seem
> to be talking about it.  I would welcome any tips, examples, insight
> and warnings you might have.
> 
> I have been experimenting and playing with it, based on their ADFS
> config (http://support.panopto.com/focus-4-articles/24-activedirectory/399-hosted-panopto-federated-authentication)
> and have stored their metadata, configured basic filters etc, but
> there is one AD attribute they want that seems problematic.  The AD
> attribute "tokenGroups".  I am unable to pull this attribute
> successfully with any tool, even powershell with the ActiveDirectory
> module, to examine it.
> http://msdn.microsoft.com/en-us/library/windows/desktop/ms680275%28v=vs.85%29.aspx
>  From what I've uncovered so far this attribute seems to be some kind
> of conglomerate value that has to then be broken down into SID's and
> enumerated.  Even if I can get my hands on that attribute, I'm not
> sure how I would pull off the enumeration of it in Shibboleth.  I'm
> hoping someone out there has cracked this nut before and can show me
> how.  Any ideas?
> 
> Chuck
> Utah State University
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
 		 	   		  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120320/05949b65/attachment.html 


More information about the users mailing list