Which software is right?

Constance Morris cmorris at daltonstate.edu
Mon Apr 8 10:01:31 EDT 2013


Hi Peter,

I guess I need a better understanding of each component to know exactly what I need. Our users can authenticate via active directory on and off site, so I am guessing I do not need SAML IdP? 

Right now, our users can login both on or off site using their active directory credentials, but any links they click on inside the portal to other resources require them to login again.  

So would SP be the only component of Shibboleth I need to use for our users to be able to SSO into our portal using their active directory credentials and be considered 'logged in' to the other resources as well?

Thank you for your response and assistance in helping me! :-)

Constance  

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Peter Schober
Sent: Monday, April 08, 2013 9:15 AM
To: users at shibboleth.net
Subject: Re: Which software is right?

* Constance   Morris <cmorris at daltonstate.edu> [2013-04-08 14:56]:
> We currently use Active Directory (AD) over our LDAP for 
> authentication. However, we need for our clients to be able to SSO 
> into our portal and be able to access all resources within from that 
> initial login authentication. I've been considered CAS, but came 
> across Shibboleth.net and thought I would give it a try.
[...]
> Also, which is the preferred OS to use....Linux or Windows (we have 
> both)?

More specifically, the OS for the Service Provider will be dictated by your current portal, as the SP ideally will run on that same machine.

If you need to access the portal via SAML for your own users (instead of having two seperate protocols for interal vs. external subjects), for example for off-site access (assuming your MS-Active Directory is not an option there) you'd also needed to install and configure a SAML IdP.
Given that the IdP is in Java I'd recommend a platform which provides security fixes for the JVM in a timely matter.
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list