A scenario to lookup Active Directory attributes
Rikard Braathen
rikard.braathen at gmail.com
Wed Oct 9 07:59:14 EDT 2013
I've got a scenario like this...
1. User accesses a protected resource
2. Shibboleth SP redirect to external IdP
3. login through external IdP gives username at email.com
4. Would it be possible to HERE make a lookup to Active Directory, search
for the username at email.com and retrieve the SAMAccountName together with
the groups that the mailaddress (user) belongs to?
What would be the procedure or best practise to accomplish this? Would I
need to also install Shibboleth IdP in order to make the lookup to the AD?
The external IdP can't talk to the internal AD.
Maybe this should be designed in some other way? And maybe this is not how
you do it at all. I'm grateful for any ideas or suggestions.
-- Rikard
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131009/9bbd2ff5/attachment.html
More information about the users
mailing list