Google Apps with shibb ECP
David Gersic
dgersic at niu.edu
Tue Aug 5 14:26:05 EDT 2014
>>> On 8/4/2014 at 12:06 PM, Rob Gorrell <rwgorrel at uncg.edu> wrote:
> I'm curious how Google schools deploying shibb for an SSO deal with the
> mobile device issue since accessing email on handheld devices has become a
> fundamental expectation... do most still send your passwords to Google for
> local auth in conjunction with SSO for the web components as we are, or is
> there a better approach?
We're doing GAFE here, have been for a couple of years, and are using Shib for the webmail service. For the mobile services, there's a separate "Google Password" that the user has to get, and use. This is distinct from their "University Password" that works everywhere else. (This was a deliberate design choice.)
One of the driving "wants" behind us moving to GAFE was the perception that the "mobile device issue" was one that we needed to solve, and would be best solved by GAFE (vs. any other possibilities). In reality, we have ~150K GAFE accounts, and the last time I looked ~400 of them are being accessed by mobile devices.
If you're using GAFE, you might check the reports thing that shows your users' access patterns. Maybe yours is much different from ours. Here, it seems to me that the "mobile device issue" isn't really much of an issue at all.
More information about the users
mailing list