configuration for two unrelated servers
Ewert, Craig
Craig.Ewert at dish.com
Fri Mar 15 13:27:27 EDT 2013
Thanks, Kevin. I thought from first principles that must be the case.
If I only wanted SSO, and could let W handle it's own security, could I have the W app send a Shibboleth/Login to A and have A hand back the SAML assertions it got from the IdP? In headers, or POST body or any which way? A and W are both behind a big ole firewall in a datacenter, so I'm not worried about traffic between them.
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Kevin P. Foote
Sent: Friday, March 15, 2013 11:24 AM
To: Shib Users
Subject: Re: configuration for two unrelated servers
On Fri, 15 Mar 2013, Ewert, Craig wrote:
> Maybe I'm crazy, so please confirm.
>
> I have two servers A (for apache) and W (for weblogic) on different machines. Is it possible to configure shibboleth on A to secure the resources on W without having A act as proxy and catch & forward all Ws traffic? Or is that a crazy desire that could never be secure?
>
If you are going to "secure the resource on W" through the SP on apache then you are proxying. All the "secured" traffic needs to flow through apache.
The SP can not protect things it does not know about..
------
thanks
kevin.foote
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list