proxy-authentication to SP

Peter Schober peter.schober at univie.ac.at
Thu Apr 30 08:35:35 EDT 2015


* Ulf Seltmann <seltmann at ub.uni-leipzig.de> [2015-04-30 14:09]:
> Is it somehow possible to the "foo SP" to take the session credentials
> of the client (_shibsession cookie maybe) and perform an authentication
> to "bar SP" in order to prove an authenticated Client and access its
> Data?

Nope.

There's the complex topic of delegation of SAML assertions,
cf. https://spaces.internet2.edu/display/ShibuPortal/Home

But what Dave described in his post (basically giving the SP that does
interact with the subject "admin" rights on the other SP, to
impersonate the subject without any proof, via some other
channel/protocol) is the shortcut usually taken to avoid having to
implement delegation.
-peter


More information about the users mailing list