Kerberos TGS with Shibboleth IdP
King, David
dsmk at bu.edu
Tue Apr 28 09:16:39 EDT 2015
Hello,
I am working on switching a large application from our home brew legacy authentication system to Shibboleth. We are currently running a Shibboleth IdP version 2.x with plans to upgrade to IdP 3.x in the future. The Shibboleth IdP is using the JAAS Username/Password handler (with Duo for second factor).
The legacy authentication system is designed to provide Kerberos TGS for specific services. The application uses those TGS values to authenticate with various other components such as our mainframe and some historical directory servers. I saw some references to this 3-tier model back in 2008-2010 but nothing recent.
How are people addressing this need using SAML 2.0 with Shibboleth IdP 2.x?
Is this easier/possible with the recently released IdP 3.0?
Thanks,
David
--
[http://www.bu.edu/brand/files/2012/10/master-logo-small.gif] David King | Senior Technical Architect, Information Services & Technology
111 Cummington Mall | Boston University | Boston, Massachusetts 02215
617.353.8250 | dsmk at bu.edu
Listen. Learn. Lead.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150428/bffcea62/attachment-0001.html>
More information about the users
mailing list