Active Directory as Authentication Source
Cantor, Scott
cantor.2 at osu.edu
Thu Mar 5 14:15:10 EST 2015
On 3/5/15, 1:53 PM, "Michael Dahlberg" <olgamirth at gmail.com> wrote:
>I believe I'm going to have to use Kerberos anyway to utilize the SSO
>capabilities of Shibboleth. I can currently query AD for the various
>attributes that I pass to the SPs, but to maintain an SSO environment,
>wouldn't I need the ticketing capabilities of Kerberos?
No, not unless you mean Kerberos in the SPNEGO sense, desktop
authentication to the IdP. SSO across SPs is just handled by the cookie
managed session the IdP handles, it has nothing to do with how you
authenticate, and is never stronger than a cookie.
-- Scott
More information about the users
mailing list