Using Shibboleth Identity Provider for Users Authenticated on an External Shibboleth System
Dave Eisen
dkeisen at sequoiars.com
Mon Sep 17 19:39:03 EDT 2012
Greetings.
I am looking to develop a centralized service to provide authentication services to all of my company's hosted platforms. The bulk of the users will need to be authenticated against third party systems local to their organization. Some of the organizations use LDAP, some use Shibboleth, some use other protocols. We do not at this time need to maintain our own internal login/password files.
We will also need data acquisition services getting additional information about these users such as email address, street address, user type, etc.
The natural way to implement this would be for my company to host our own Shibboleth Identity Provider which does whatever parsing and configuration management needed to support this feature and then sends the request for the "real" authentication to the third party that knows the user. It is natural, but I do not know if it is technically possible.
It is clear from the Shibboleth documentation that I can forward an authentication request to an LDAP system. I'm wondering how I support users managed by a third party Shibboleth system.
Is it possible to configure my Identity Provider to authenticate user foo using Shibboleth at bar.com's Identify Provider? Different Identity Providers for different users? How do I do this?
Thanks.
Dave Eisen
Sequoia Retail Systems
dkeisen at sequoiars.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120917/99101c13/attachment.html
More information about the users
mailing list