shibboleth authentication with Active Directory UPN
Mauro Minella
Mauro.Minella at microsoft.com
Fri Sep 14 17:47:46 EDT 2012
Hi all.
I have a Windows Server 2008R2 Domain Controller which is so configured in my test environment:
- Domain name: shibdomain.local
- Machine name: shibidp.shibdomain.local
- DNS name for the same machine (in order to be reached from Internet and install SSL certificate): shibdomain.eduteamit.com
- Additional UPN suffix: shibdomain.eduteamit.com (you can set it in AD Domains and Trusts, in order to be able to use it for the users' UPN)
- Then I have the following user:
o domain account: shibdomain\johns
o upn: john.smith at shibdomain.eduteamit.com<mailto:john.smith at shibdomain.eduteamit.com>
o password: abc123ABC
I've installed Shibboleth 2.3.5 on Windows Active Directory and it seems working: when I go to https://sp.testshib.org/ , enter my test domain (shibidp.eduteamit.com) and enter my credentials (johns, abc123ABC) I am properly authenticated.
The point is that my users are used to be authenticated (even on their Windows machine) through their upn.
QUESTION: how can the users be authenticated with the upn (john.smith at shibdomain.eduteamit.com<mailto:john.smith at shibdomain.eduteamit.com>, abc123ABC), or even with the domain account (shibdomain\johns, abc123ABC)? It looks like that only the flat domain username (without domain name\) is accepted.
I hope my question is clear. If you want to try, just go to https://sp.testshib.org/ and enter https://shibidp.eduteamit.com/idp/shibboleth with my user above.
Thank you for your help
Mauro
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120914/948edd3c/attachment-0001.html
More information about the users
mailing list