SOA Security

Cantor, Scott cantor.2 at osu.edu
Mon Feb 23 10:09:00 EST 2015


You can also ue OAuth of course, though that's not generally true 
delegation. Nothing is stopping you, there doesn't need to be anything in 
the IdP to allow that to work in simple cases.

-- Scott

On 2/23/15, 3:06 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 2/23/15, 2:03 PM, "Arnal, Pascal" <Pascal.Arnal at lacapitale.com> wrote:
>
>> 
>>Could you please tell me how to set-up the components so the first SP 
>>session or cookies are passed to the second SP? Is it related to 
>>Enhanced 
>>Client or Proxy (ECP)?
>
>You can't, that would be insecure.
>
>It's delegation. The only delegation solution we implemented was in an 
>extension [1] and we haven't ported that extension into V3 yet because 
>adoption has been minimal.
>
>And yes, it requires ECP in the REST client to use.
>
>-- Scott
>
>[1] https://spaces.internet2.edu/display/ShibuPortal/Home
>





More information about the users mailing list