proxy-authentication to SP
Dave Perry
Dave.Perry at hull-college.ac.uk
Thu Apr 30 08:26:36 EDT 2015
Your ascii art made it!
I assume that there is data specific to each user on both SPs' applications? And if so, why not simply have a mechanism where bar and foo can talk to each other directly (behind the scenes) in the appropriate direction. E.g. foo SP asks bar SP for the data on user x (where user x has been set by the shibboleth session).
Dave
_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group
Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930
* Need a fast reply? Try elearning at hull-college.ac.uk *
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Ulf Seltmann
Sent: 30 April 2015 13:09
To: users at shibboleth.net
Subject: proxy-authentication to SP
Hello shibboleth users.
I have a question regarding proxying authentication requests to a shibboleth-sp. First i want to describe the structure that we intend to build (i hope my ASCII-Art makes it):
__________
/ \
| Client |-------\
\__________/ |
| |
__________ _____|____ |
/ \ / \ |
| bar SP |--------| foo SP | |
\__________/ \__________/ |
| | |
| _____|____ |
| / \ |
\-------------| IdP |-------/
\__________/
The client is the webbrowser and is attempt to authenticate when accessing the "foo SP".
As far as i understand "foo SP" waits for the client to authenticate on the IdP which then "validates" the Session between the client and "foo SP"
The SP "bar SP" is not accessed directly by the client, but by "foo SP"
during the session between the client and "foo SP" to access data related to the client.
Since we have no authentication credentials we are so far not able to secure the communication between "foo SP" and "bar SP" on a basis of a valid authenticated session.
And here comes my Question:
Is it somehow possible to the "foo SP" to take the session credentials of the client (_shibsession cookie maybe) and perform an authentication to "bar SP" in order to prove an authenticated Client and access its Data?
I hope i could explain it sufficiently, you may have guessed that english is not my native language :)
thanks in advance
--
Ulf Seltmann
Webmaster
Universitätsbibliothek Leipzig
Beethovenstrasse 6
04107 Leipzig
fon: +49 (0)341 97 30 51 0
mail: seltmann at ub.uni-leipzig.de
**********************************************************************
This message is sent in confidence for the addressee
only. It may contain confidential or sensitive
information. The contents are not to be disclosed
to anyone other than the addressee. Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission. Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College. Nothing in this
message should be construed as creating a contract.
Hull College owns the email infrastructure, including the contents.
Hull College is committed to sustainability, please reflect before printing this email.
**********************************************************************
TEXT
More information about the users
mailing list