Shibboleth IdP using ADFS for authentication source

Dave Perry Dave.Perry at hull-college.ac.uk
Mon Jan 26 04:39:30 EST 2015


OK thanks all, once ADFS has gone public (final testing stages, apparently) I'll request some IT resource to get this working with the new one.

Dave

_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group

Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930

* Need a fast reply? Try elearning at hull-college.ac.uk *

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Peter Schober
Sent: 26 January 2015 09:37
To: users at shibboleth.net
Subject: Re: Shibboleth IdP using ADFS for authentication source

* Dave Perry <Dave.Perry at hull-college.ac.uk> [2015-01-26 10:28]:
> What we're looking at is what you describe Dave, but I'll be setting up the IdP - the workflow is this:
> - student logs in to O365 via adfs
> - student wants to open up an eresource, protected by shibboleth, so 
> our idp says 'is there an adfs session' and if so uses it but if not 
> prompts for an adfs login then takes the student to that eresource 
> when successful
> - student now has a shibboleth session to roam our eresources

Scott already gave you the answer how to make the Shib IDP (always) defer to MS-ADFS (whatever that means, technically) for authentication.
Note that this would then also send people there when they're accessing your internal SAML SPs.

> Maybe that is clearer than the first way i wrote it. We have one or 
> two sites we might control the SP for in house, but we would want the 
> shibboleth login page to be their front end. Otherwise, if adfs 
> becomes our idp, we'd have to change our subscription details with 
> about 50 other providers.

By externalizing authentication from the Shib IDP to something else the Shib IDP remains the SAML IDP issuing assertions to all your SAML SPs (internal or external). I.e., that authentication changed at the IDP is private to the IDP, the SPs know nothing about that.

> My team (elearning) isn't part of IT (we're based in the library and 
> answer to the libraries + elearning manager), and we can provide 
> better support to students with access to shibboleth logs (we wouldn't 
> get ADFS log access).

Since the Shib IDP would remain the SAML IDP, nothing would change on that front either. The Shib IDP would continue logging as before.
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

**********************************************************************
This message is sent in confidence for the addressee
only. It may  contain confidential or sensitive
information.  The contents are not to be disclosed
to anyone other than the addressee.  Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission.  Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College.  Nothing in this
message should be construed as creating a contract.

Hull College owns the email infrastructure, including the contents.

Hull College is committed to sustainability, please reflect before printing this email.
**********************************************************************

TEXT


More information about the users mailing list