Is Shibboleth a match to replace our multi-factor authentication system ?
Peter Schober
peter.schober at univie.ac.at
Wed Sep 12 06:49:38 EDT 2012
* Patrick Rynhart <P.Rynhart at massey.ac.nz> [2012-09-11 22:35]:
> 1. Most Shibboleth installation online appear to be for integration
> with a Federation (InCommon, e.g.). I believe that our arrangement
> is simplier
I think that you will quickly find that having a single system that
doesn't (technically) care whether some SP is "internal" or "external"
(by whatever definition) makes a lot of sense, policy-wise and
practically. (E.g. I won't /necessarily/ trust some campus-SP more
than some service provided by another university or research community
or vendor.)
There's no seperate documentation for this case because it's not
really a special case. When you can do federation by defintion you can
also use it internally, with the same powerful tools. That was a key
point for me for using "the federation system" as an internal websso
system as well.
-peter
More information about the users
mailing list