CAS/shib integration
Peter Schober
peter.schober at univie.ac.at
Thu Jan 23 03:47:23 EST 2014
* Paul B. Henson <henson at csupomona.edu> [2014-01-22 21:54]:
> I'm tentatively leaning towards implementing Unicon's
> shib-cas-authenticator module, it seems the most technically
> superior choice (modulo the critical security flaw in their initial
> release :) ). Just wondering if anybody looked at that and ended up
> going with the basic remote user method instead, and if so, why?
RemoteUser is quicker and easier to setup (the IDP even defaults to
it, so any setup happens outside Shib). Other than that it's main
drawback seems to be the lack of support for forceAuthn and isPassive
(if those ever become important to your SAML 2.0 SPs).
-peter
More information about the users
mailing list