Understanding flow / federation
Bo Lorentsen
bl at moch.dk
Mon Sep 24 13:42:13 EDT 2012
On 2012-09-24 19:16, Cantor, Scott wrote:
> At no point did I say "not possible". I said "not provided without
> additional work".
Ok ok, point taken ... developers can make what is not there ... i know.
> Chances are you're reading way too much technical specificity into their
> fluffy marketing-oriented concepts. But you don't do federation to do
> IdPs, you do them to protect SPs.
Yeps, my head had been spinning trying to connect all the dots, and
fluffy marketing-oriented concepts don't help, I totally agree :-)
> If you have two groups of users with IdPs and no systems they want to access, you have nothing to do.
I think I understand that much :-)
> Then you already have IdPs. You don't need to add one.
I have another company, that have a large MS AD full of users that likes
to use some of our services without login, I dare to believe this is
called SSO.
> If that's your reason for adding a gateway, that's fine, but as I
> said, we don't provide a gateway without additional effort. Others do.
That is properly something my spinning head did not grasp, until now.
/BL
More information about the users
mailing list