Integration of Shibboleth with existing login functionality

Tallant, Marcus MTallant at eab.com
Mon May 20 15:33:23 EDT 2013


I am looking to use implement a SAML service provider, and am looking at installing Shibboleth.  Our application already has an existing login mechanism that does is not SAML/Shibboleth, and if we install a Shibboleth SP that protects our application, it must be able to somehow query the application it is protecting to determine whether to use Shibboleth to authenticate the user, and only in that case to redirect the use to the appropriate IDP.  So, really I have two questions:


1.        Can a Shibboleth SP installed on Apache, protecting an application (say, a Java App), first query the application before determining if it will direct the user to their identity provider or use an alternative login mechanism?

2.        If the app will  use a Shibboleth IDP, can the Shibboleth SP receive info from the protected application telling it which IDP to use (as if the application was used to discover the IDP)?

Thanks,

Marcus Tallant


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130520/cf9d9350/attachment.html 


More information about the users mailing list