Shibboleth IdP as the hub in a hub and spoke federation
Scott Koranda
skoranda at gmail.com
Mon Mar 3 17:44:51 EST 2014
On Mon, Mar 3, 2014 at 2:39 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 3/3/14, 3:17 PM, "Scott Koranda" <skoranda at gmail.com> wrote:
>>
>>I am especially interested in hearing of solutions that do not use the
>>REMOTE_USER login handler in order to support isPassive and forced
>>re-authentication.
>
> Sticking only to the question of how one could do it with Apache plus my
> SP, I suppose that could probably be managed with the External login
> handler. A small servlet would handle the relaying of policy flags into
> /Shibboleth.sso/Login.
>
Constraining the solution to using the Shibboleth SP and Apache is possible
for this particular use case.
If I am willing to pay the price/overhead of developing my own login handler
due to other motivations, there is no particular reason to have to use the
External login handler, correct?
Indeed using the MCB as a base and developing a MCB sub-module(s) to
act as a proxy in conjunction with the Shibboleth SP and Apache is also
a viable approach correct?
Thanks,
Scott K
More information about the users
mailing list