shibboleth authentication with Active Directory UPN

Mauro Minella Mauro.Minella at microsoft.com
Fri Sep 14 17:47:46 EDT 2012


Hi all.

I have a Windows Server 2008R2 Domain Controller which is so configured in my test environment:

-          Domain name: shibdomain.local

-          Machine name: shibidp.shibdomain.local

-          DNS name for the same machine (in order to be reached from Internet and install SSL certificate): shibdomain.eduteamit.com

-          Additional UPN suffix: shibdomain.eduteamit.com (you can set it in AD Domains and Trusts, in order to be able to use it for the users' UPN)

-          Then I have the following user:

o   domain account: shibdomain\johns

o   upn: john.smith at shibdomain.eduteamit.com<mailto:john.smith at shibdomain.eduteamit.com>

o   password: abc123ABC

I've installed Shibboleth 2.3.5 on Windows Active Directory and it seems working: when I go to https://sp.testshib.org/ , enter my test domain (shibidp.eduteamit.com) and enter my credentials (johns, abc123ABC) I am properly authenticated.
The point is that my users are used to be authenticated (even on their Windows machine) through their upn.

QUESTION: how can the users be authenticated with the upn (john.smith at shibdomain.eduteamit.com<mailto:john.smith at shibdomain.eduteamit.com>, abc123ABC), or even with the domain account (shibdomain\johns, abc123ABC)? It looks like that only the flat domain username (without domain name\) is accepted.

I hope my question is clear. If you want to try, just go to https://sp.testshib.org/ and enter https://shibidp.eduteamit.com/idp/shibboleth with my user above.

Thank you for your help

Mauro
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120914/948edd3c/attachment-0001.html 


More information about the users mailing list