SOA Security
Arnal, Pascal
Pascal.Arnal at lacapitale.com
Fri Feb 27 08:55:15 EST 2015
I will change the approch and if possible I will use x509 auth for the application.
So the scenario will be :
1 - The user call the SP of the application and fill his credentials
2 - The SP of the application redirect the user to the application
3 - The application call the SP of service with X509 cert and User HTTP Headers
4 - The SP of service redirect the application to the service
Can you confirm that it's possible ?
Thanks
-----Message d'origine-----
De : users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] De la part de Cantor, Scott
Envoyé : 25 février 2015 13:45
À : Shib Users
Objet : Re: SOA Security
On 2/25/15, 6:21 PM, "Arnal, Pascal" <Pascal.Arnal at lacapitale.com> wrote:
>What's concretly the next step please ?
Setting up ECP doesn't help you, this isn't just ECP, it's something we layered on top of ECP and doesn't use that code.
https://spaces.internet2.edu/display/ShibuPortal/Configuring+Shibboleth+Del
egation+for+a+Portal
You'd have to install the delegation extension and configure it in place of the regular SSO and ECP profile code, and set up whatever policies have to be set up for that to work.
Then you'd need an web service client with some fairly sophisticated capabilities that do not exist outside of specifically built examples.
Absolutely nothing off the shelf will work. Unless you have one or build one, this isn't going to work anyway.
OAuth is not remotely close to the same security semantics of what this mechanism does, but it is much simpler (that's why it's simpler, it solves a much less complex problem). Chances are you'll be a lot happier with that, but if you really need federated delegation, there's no simple or plug and play answer. There's not enough demand for us to work on making it simpler.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
AVIS: Ce courriel privilégié et confidentiel est destiné à la seule personne ou entité à laquelle il est adressé. Pour toute autre personne, toute action prise en rapport à ce courriel ainsi que toute lecture, reproduction, transmission et/ou divulgation d'une partie ou de l'ensemble de celui-ci est interdite. Si vous n'êtes pas la personne autorisée à recevoir ce courriel, S.V.P. le retourner à l'expéditeur et le détruire. Bien que ce courriel ait été traité contre les virus, il est de la responsabilité du destinataire de s'assurer que l'envoi en est exempt. Nos communications avec vous peuvent contenir des renseignements confidentiels ou protégés par le secret professionnel. Si vous désirez que nous communiquions avec vous par un autre moyen de transmission que le courrier électronique ordinaire non sécurisé, veuillez nous en aviser.
NOTICE: This privileged and confidential email is intended only for the individual or entity to whom it is addressed. With regard to all others, any action related with this email as well as any reading, reproduction, transmission and/or dissemination in whole or in part of the information included in this email is prohibited. If you are not the addressee, immediately return the email to sender prior to destroying all copies. Even if this email is believed to be free from any virus, it is the responsibility of the recipient to make sure that it is virus exempt. Our communications to you may contain confidential information or information protected under solicitor-client privilege. Please advise if you wish us to use a mode of communication other than regular, unsecured e-mail in our communications with you.
More information about the users
mailing list