SOA Security
Cantor, Scott
cantor.2 at osu.edu
Mon Feb 23 10:09:00 EST 2015
You can also ue OAuth of course, though that's not generally true
delegation. Nothing is stopping you, there doesn't need to be anything in
the IdP to allow that to work in simple cases.
-- Scott
On 2/23/15, 3:06 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>On 2/23/15, 2:03 PM, "Arnal, Pascal" <Pascal.Arnal at lacapitale.com> wrote:
>
>>
>>Could you please tell me how to set-up the components so the first SP
>>session or cookies are passed to the second SP? Is it related to
>>Enhanced
>>Client or Proxy (ECP)?
>
>You can't, that would be insecure.
>
>It's delegation. The only delegation solution we implemented was in an
>extension [1] and we haven't ported that extension into V3 yet because
>adoption has been minimal.
>
>And yes, it requires ECP in the REST client to use.
>
>-- Scott
>
>[1] https://spaces.internet2.edu/display/ShibuPortal/Home
>
More information about the users
mailing list