Kerberos integration with shib Idp authentication

Cantor, Scott cantor.2 at osu.edu
Thu Dec 10 14:18:24 EST 2015


On 12/9/15, 8:26 PM, "users on behalf of C G" <users-bounces at shibboleth.net on behalf of ci_98yr at yahoo.com> wrote:



>A basic question (yep my ignorance on this)
>Is it possible to integrate Kerberos with a standalone shib Idp. The authentication need to happen at Idp and no credentials (except userid) is shared between Idp and Kerberos system.  Basically Idp front ending the Kerberos before tgt and access ticket were issued by Kerberos. Any sample configs and pointers on this much appreciated!

I can't make any sense of the specifics of that question, but if you're talking about SPNEGO, it was added in 3.2, and there's a detailed explanation of how to use it in the IdP documentation.

-- Scott



More information about the users mailing list