Active Directory as Authentication Source

Cantor, Scott cantor.2 at osu.edu
Thu Mar 5 14:15:10 EST 2015


On 3/5/15, 1:53 PM, "Michael Dahlberg" <olgamirth at gmail.com> wrote:

>I believe I'm going to have to use Kerberos anyway to utilize the SSO 
>capabilities of Shibboleth.  I can currently query AD for the various 
>attributes that I pass to the SPs, but to maintain an SSO environment, 
>wouldn't I need the ticketing capabilities of Kerberos?

No, not unless you mean Kerberos in the SPNEGO sense, desktop 
authentication to the IdP. SSO across SPs is just handled by the cookie 
managed session the IdP handles, it has nothing to do with how you 
authenticate, and is never stronger than a cookie.

-- Scott



More information about the users mailing list