Understanding flow / federation

Cantor, Scott cantor.2 at osu.edu
Mon Sep 24 13:16:58 EDT 2012


On 9/24/12 1:05 PM, "Bo Lorentsen" <bl at moch.dk> wrote:

>So when others are talking about a federation in this Oasis world (where
>you have some kind of trust between more than one group of users /
>idP's) it is not possible to be using shibboleth idP ?

At no point did I say "not possible". I said "not provided without
additional work".

Chances are you're reading way too much technical specificity into their
fluffy marketing-oriented concepts. But you don't do federation to do
IdPs, you do them to protect SPs. If you have two groups of users with
IdPs and no systems they want to access, you have nothing to do.


>ped to make it possible to let (our) users login using both our own
>idP or some of our customers AD (ADFS2), using the same framework.

Then you already have IdPs. You don't need to add one.

>Our sites are all in a pure Linux environment, so the more I could use
>Linux the better, as MS servers are a bit of a blackbox to me :-)

If that's your reason for adding a gateway, that's fine, but as I said, we
don't provide a gateway without additional effort. Others do.

-- Scott




More information about the users mailing list