question about shibboleth and perl script redirection

Joseph Norris jozefn at sonic.net
Sat Oct 6 17:11:55 EDT 2012


Hi Nate,

Thank you for your response.  Let me try to explain this a little 
better. My login script is run via the browser.  I have used this script 
to redirect to cas server with success by passing parameters in the 
query_string that allowed me to obtain a response from the CAS server in 
the form of xml document - either success or failure depending upon the 
user/pass.

I do not know what to put in the query string to the the shibboleth server.

In the case of CAS I send a identification token with a url to return to 
which is my login script - which expects a xml response that I use to 
determine success or failure.  I am unsure what the query_string should 
be for shibboleth server.

Thanks

On 10/06/2012 12:41 AM, Nate Klingenstein wrote:
> Joseph,
>
>> I have a login script that logs into my system and I need to redirect
>> the users to the shibboleth identity service provider.
> It's a little unclear what you mean by login script and "identity service provider".  I'm guessing you meant a script that runs on the client's machine that is responsible for authenticating to an IdP.
>
> If I'm right, you want to first decide on the capabilities of the script.  I'd recommend you use the ECP profile if you want to avoid user or client web browser interaction.
>
> https://wiki.shibboleth.net/confluence/display/SHIB2/ECP
>
>> I am floundering in two aspects:
>>
>> 1)  In my redirect what do I need to provide in the query string to the
>> provider?
> Depends on how the script invokes the authentication process.  If it starts by accessing an SP, then that SP will generate an AuthnRequest in a "SAMLRequest=encodedGoo" query parameter that your client will play to the IdP.
>
> Otherwise, the simplest choice would be:
>
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUnsolicitedSSO
>
>> 2)  If I get number 1 correct what will be the return?  a piece of xml
>> that I can slice'n'dice?
> Generally, an encrypted piece of XML(an assertion wrapped in a response) that you'll be able to slice'n'dice if you have the right decryption key.  The IdP can disable this encryption if need be.
>
>> Thank you for any and all help - example redirect code would be
>> fantastic.  I just need to know what needs to be sent.
> The ECP page links to several great examples, including one in Perl.  The UnsolicitedSSO query string dance is so simple it sort-of precludes example scripts.  You should have no problem with that.
>
> Hope I interpreted everything right, and it gets you a little further along.  Whether or not, we're ready to field more...
>
> Thanks,
> Nate.
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
>

-- 
#Joseph Norris (Linux/Apache/Mysql/Perl - what else is there?)
print @c=map chr $_+100,(6,17,15,16,-68,-3,10,11,
16,4,1, 14,-68,12,1,14,8, -68,4,-3,-1,7,1,14,-68,
-26,11,15,1,12, 4,-68,-22,11,14,14,5,15,-90);



More information about the users mailing list