Alternatives to DS deployment
Caskey, Paul
pcaskey at utsystem.edu
Tue Jun 18 16:35:59 EDT 2013
You may want to take a look at the Embedded Discovery Service (EDS):
https://wiki.shibboleth.net/confluence/display/EDS10/Embedded+Discovery+Service
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Eric Goodman
Sent: Tuesday, June 18, 2013 3:22 PM
To: Shib Users
Subject: Alternatives to DS deployment
Was just looking at the instructions for installing the Discovery Service (https://wiki.shibboleth.net/confluence/display/SHIB2/DSInstall) and it says the following:
"The first question you should ask is whether you need to install the DiscoveryService<https://wiki.shibboleth.net/confluence/display/SHIB2/DiscoveryService>. If you're working in a non-Java environment, you may find it easier to build a selection page in a more native fashion, or you may find that the SP alone provides enough rudimentary support to get started."
I'm not sure I'm fully grokking the advice here. Are these the kinds of alternatives being suggested? Are there other common modes to consider? Or is something else implied here?
* link to an existing WAYF/DS (such as InCommon's WAYF/Discovery Service) rather than deploying locally
* present a static list of idp-initiated SSO links
* present a static list of IdPs, then initiate actual authentication requests by calling SAML libraries and redirecting the user directly in your app (instead of having the SP do this)
Thanks,
--- Eric
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130618/1e158112/attachment.html
More information about the users
mailing list