Using Shibboleth Identity Provider for Users Authenticated on an External Shibboleth System

Cantor, Scott cantor.2 at osu.edu
Tue Sep 18 11:59:30 EDT 2012


On 9/18/12 11:53 AM, "Dave Eisen" <dkeisen at sequoiars.com> wrote:

>I understand this, but this is disappointing to me for several reasons:
> 
>1.      
>I want to centralize configuration so I do not have to have all client
>systems (our suite of hosted platforms) understand how to configure
>various types of authentication.
>2.      
>I want to centralize parsing of returned information so we do not have to
>have all client systems managing conversion of external data to a format
>useful for our applications. This is to some degree inevitable as the
>various applications
> might have different needs, but some centralization seems useful here.

You could push out centrally-maintained configurations.

>3.
>I want a common API to provide to my application programmers who in
>general know nothing about authentication, SAML, LDAP, etc. What you¹re
>providing works, but does not meet this goal.

Why wouldn't it? A given SAML implementation has a uniform interaction
pattern regardless of the IdP.

-- Scott




More information about the users mailing list