Re: Institutional Shibboleth IdP with Amazon Web Services SP?

Randy Wiemer wiemerr at hotmail.com
Wed Jul 2 17:20:47 EDT 2014


This AWS feature appears to have a dependency on a Microsoft WIF extension for SAML2 which is no longer downloadable from the Microsoft Connect site.


http://blogs.msdn.com/b/card/archive/2011/05/16/announcing-the-wif-extension-for-saml-2-0-protocol-community-technology-preview.aspx



Randy



From: Liam Hoekenga
Sent: ‎Wednesday‎, ‎July‎ ‎2‎, ‎2014 ‎4‎:‎00‎ ‎PM
To: Shib Users





Is anyone doing it with a "federated proxy" (i.e. http://aws.amazon.com/code/8383453795065208 )
It's not clear to me what advantage this proxy provides..




Liam




On Wed, Jul 2, 2014 at 1:47 PM, Jim Fox <fox at washington.edu> wrote:





I’ve been asked whether our IdP can readily support AWS logins as outlined
in:http://docs.aws.amazon.com/STS/latest/UsingSTS/STSMgmtConsole-SAML.html and
http://blogs.aws.amazon.com/security/post/TxRTTT5PLUE6B5/How-to-use-Shibboleth-for-single-sign-on-to-the-AWS-Management-Console

A quick read gave me the impression it should almost straightforward, but I would appreciate hearing from other institutions with generic
Shibboleth IdP (i.e., not hosted at AWS) that have succeeded (or failed!) providing institutional authN/attributes to AWS service via
institutional IdP.



I did this a month or so ago.  It worked as advertised.

Jim
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140702/0c1ca00b/attachment-0001.html 
-------------- next part --------------
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list