Shibboleth and LDAP
David Bantz
dabantz at alaska.edu
Mon Jan 28 15:35:00 EST 2013
On Mon, 28 Jan 2013, at 11:07 , "Raper, William" <braper at iccohio.com> wrote:
> On the web page for Shibboleth Identity Provider, it lists under the Key Features “Out of the box support for LDAP, Kerberos, web server and Servlet Container based authentication systems”.
>
> Does this mean that Shibboleth Identity Provider will use an LDAP store as a source of users to authenticate,
Yes. LDAP (or AD variant) or Kerberos and others may be used as the back-end source of authentication.
The relying service or application receives a SAML assertion indicating authentication (and optionally, attributes), but never sees the users' credentials.
> or that it will act as a proxy for applications that use the LDAP protocol?
No. "LDAP authentication" entails the service or application itself receives the user's credentials, turns around and attempts to bind as the user.
David Bantz
UA OIT IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130128/7d349640/attachment.html
More information about the users
mailing list