Shibboleth IdP as the hub in a hub and spoke federation

Scott Koranda skoranda at gmail.com
Mon Mar 3 17:44:51 EST 2014


On Mon, Mar 3, 2014 at 2:39 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 3/3/14, 3:17 PM, "Scott Koranda" <skoranda at gmail.com> wrote:
>>
>>I am especially interested in hearing of solutions that do not use the
>>REMOTE_USER login handler in order to support isPassive and forced
>>re-authentication.
>
> Sticking only to the question of how one could do it with Apache plus my
> SP, I suppose that could probably be managed with the External login
> handler. A small servlet would handle the relaying of policy flags into
> /Shibboleth.sso/Login.
>

Constraining the solution to using the Shibboleth SP and Apache is possible
for this particular use case.

If I am willing to pay the price/overhead of developing my own login handler
due to other motivations, there is no particular reason to have to use the
External login handler, correct?

Indeed using the MCB as a base and developing a MCB sub-module(s) to
act as a proxy in conjunction with the Shibboleth SP and Apache is also
a viable approach correct?

Thanks,

Scott K


More information about the users mailing list