Shibboleth IdP using ADFS for authentication source
Dave Perry
Dave.Perry at hull-college.ac.uk
Mon Jan 26 04:27:39 EST 2015
What we're looking at is what you describe Dave, but I'll be setting up the IdP - the workflow is this:
- student logs in to O365 via adfs
- student wants to open up an eresource, protected by shibboleth, so our idp says 'is there an adfs session' and if so uses it but if not prompts for an adfs login then takes the student to that eresource when successful
- student now has a shibboleth session to roam our eresources
Maybe that is clearer than the first way i wrote it. We have one or two sites we might control the SP for in house, but we would want the shibboleth login page to be their front end. Otherwise, if adfs becomes our idp, we'd have to change our subscription details with about 50 other providers.
My team (elearning) isn't part of IT (we're based in the library and answer to the libraries + elearning manager), and we can provide better support to students with access to shibboleth logs (we wouldn't get ADFS log access).
Dave
_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group
Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930
* Need a fast reply? Try elearning at hull-college.ac.uk *
Sent via webmail/mobile - please excuse spelling mistakes or brief messages
________________________________________
From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Dave Vernon [dvernon at loyalistcollege.com]
Sent: 23 January 2015 21:35
To: 'Shib Users'
Subject: RE: Shibboleth IdP using ADFS for authentication source
If you already have an ADFS session, and you setup your “other” protected resource to use a Shibboleth SP that talks to ADFS as the IdP, won’t that do what you want?
I don’t use O365, but we have a portal that authenticates with ADFS (no Shibboleth involved there at all). I also have a webserver (Blackboard learn) protected with Shibboleth SP.
If I login to the portal first, I am prompted to logon to ADFS, and get my token, and then get into the portal. If I then go to Blackboard it still knows my identity and logs me in without further prompts.
Conversely, if I login to Blackboard first, I am prompted to logon to ADFS, get my token, and then get into Blackboard. If I then go to the portal it still knows my identity and logs me in without further prompts.
Dave Vernon
Technology Infrastructure Specialist
dvernon at loyalistc.on.ca<mailto:dvernon at loyalistc.on.ca>
loyalistcollege.com<http://loyalistcollege.com/>
[Loyalist College]<http://www.loyalistcollege.com/>[Facebook]<https://www.facebook.com/loyalistcollege>[Twitter]<https://twitter.com/loyalistcollege>
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Dave Perry
Sent: Friday, January 23, 2015 9:36 AM
To: users at shibboleth.net
Subject: Shibboleth IdP using ADFS for authentication source
I might be being slow, but is there a step by step article somewhere for configuring this? Google hasn’t led me to anything (only stuff to do with SPs being signed in to by ADFS), and the only wiki articles I can find cover ADFS being hit first then going to Shibboleth (whereas I want to hit Shibboleth first and it look at ADFS to setup a session – and if there is on already, e.g. student has logged in to Office 365, pick that up).
Thanks,
Dave
_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group
Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930
* Need a fast reply? Try elearning at hull-college.ac.uk<mailto:elearning at hull-college.ac.uk> *
________________________________
This message is sent in confidence for the addressee only. It may contain confidential or sensitive information. The contents are not to be disclosed to anyone other than the addressee. Unauthorised recipients are requested to preserve this confidentiality and to advise us of any errors in transmission. Any views expressed in this message are solely the views of the individual and do not represent the views of the College. Nothing in this message should be construed as creating a contract.
Hull College owns the email infrastructure, including the contents.
Hull College is committed to sustainability, please reflect before printing this email.
________________________________
**********************************************************************
This message is sent in confidence for the addressee
only. It may contain confidential or sensitive
information. The contents are not to be disclosed
to anyone other than the addressee. Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission. Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College. Nothing in this
message should be construed as creating a contract.
Hull College owns the email infrastructure, including the contents.
Hull College is committed to sustainability, please reflect before printing this email.
**********************************************************************
TEXT
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 4005 bytes
Desc: image001.png
Url : http://shibboleth.net/pipermail/users/attachments/20150126/f3203a66/attachment.png
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.png
Type: image/png
Size: 1476 bytes
Desc: image002.png
Url : http://shibboleth.net/pipermail/users/attachments/20150126/f3203a66/attachment-0001.png
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image003.png
Type: image/png
Size: 1536 bytes
Desc: image003.png
Url : http://shibboleth.net/pipermail/users/attachments/20150126/f3203a66/attachment-0002.png
More information about the users
mailing list