SOA Security

Cantor, Scott cantor.2 at osu.edu
Fri Feb 27 11:54:46 EST 2015


On 2/27/15, 8:55 AM, "Arnal, Pascal" <Pascal.Arnal at lacapitale.com> wrote:

>I will change the approch and if possible I will use x509 auth for the 
>application.
>So the scenario will be :
> 1 - The user call the SP of the application and fill his credentials
> 2 - The SP of the application redirect the user to the application

I don't know what that means. If you mean SSO via SAML, ok.

> 3 - The application call the SP of service with X509 cert and User HTTP 
>Headers
> 4 - The SP of service redirect the application to the service

I don't know what that means either, but you can't use X.509 with the 
Shibboleth SP, no. You could sort of use it by using the "back door" 
feature built-in to the SP to add that as a separate way of getting a 
session established, I guess. [1]

-- Scott

[1] https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPBackDoor


More information about the users mailing list