Kerberos Authentication
Caleb Racey
caleb.racey at newcastle.ac.uk
Mon Mar 30 12:10:02 EDT 2015
We are looking at our options for Shib and SPNEGO Kerberos support and Chris Franks (the technical genius behind the SPNEGO work) is currently sorting out our shib3 roadmap. We have over 100 internal SPs so we are heavily motivated to come up with a working solution, from what we have seen so far we should be able to get something workable. We'll let the list now when we get to something concrete.
To answer Dave's question re login with role accounts there are a couple of options, you can alter the spnegoscript.js script so it looks for a user agent string (campus-ncl) in our case and only autologins in when it sees that (we than apply that change to our IE and Chrome builds) Then when you don't what to autologin unset the useragent stirng. Alternatively change the browser security setting so that it doesn't send kerb tickets to anything (IIRC setting IE security to "High" might do the trick)
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cesc Travesa
Sent: Thursday, March 26, 2015 2:15 AM
To: Shib Users
Subject: Re: Kerberos Authentication
Hi All,
This documentation (https://crypt.ncl.ac.uk/login-gateway/docs/Shibboleth_SPNEGO_Setup.pdf) is for IdP v2.x isn't it? in v3.0 can't be reused right?
Any news on approximate IdP release of when the "magical kerberos" will be working?
Cesc
________________________________
De: users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net> [users-bounces at shibboleth.net] en nombre de Dave Perry [Dave.Perry at hull-college.ac.uk]
Enviado: miércoles, 04 de marzo de 2015 1:24
Para: Shib Users
Asunto: RE: Kerberos Authentication
See here:
https://crypt.ncl.ac.uk/login-gateway/docs/Shibboleth_SPNEGO_Setup.pdf
Caleb - is there a way of giving people the option of not using this on a per-use basis? We've found that some people need to login to our shibboleth as not the user logged in to the PC (i.e. us elearning/IT folk when testing things for people).
I was going to factor it in to our new (v3) IdP from the getgo, but a little hesitant if it can't (moodle lets us login without checking the NTLM status with a bypass link, does your SPENGO setup?).
Dave
_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group
Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930
* Need a fast reply? Try elearning at hull-college.ac.uk<mailto:elearning at hull-college.ac.uk> *
Rate our service with the Library & eLearning Survey
For Students: http://library.hull-college.ac.uk/survey
For Staff: http://library.hull-college.ac.uk/staffsurvey
From: users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net> [mailto:users-bounces at shibboleth.net] On Behalf Of Arnal, Pascal
Sent: 03 March 2015 16:14
To: users at shibboleth.net<mailto:users at shibboleth.net>
Subject: Kerberos Authentication
Hi,
I would like to use my Windows Authentication with Shibboleth IDP V3 AND Shibboleth SP V2.
I followed the documentation https://wiki.shibboleth.net/confluence/display/IDP30/KerberosAuthnConfiguration
When I want to access my application, the login page of the IDP is displayed and after I filled my credentials, my application is accessible.
Now I would like to use my Windows Authentication and the Kerberos Token for not fill again my credential.
Is-it possible, and how please ?
Thanks
________________________________
AVIS: Ce courriel privilégié et confidentiel est destiné à la seule personne ou entité à laquelle il est adressé. Pour toute autre personne, toute action prise en rapport à ce courriel ainsi que toute lecture, reproduction, transmission et/ou divulgation d'une partie ou de l'ensemble de celui-ci est interdite. Si vous n'êtes pas la personne autorisée à recevoir ce courriel, S.V.P. le retourner à l'expéditeur et le détruire. Bien que ce courriel ait été traité contre les virus, il est de la responsabilité du destinataire de s'assurer que l'envoi en est exempt. Nos communications avec vous peuvent contenir des renseignements confidentiels ou protégés par le secret professionnel. Si vous désirez que nous communiquions avec vous par un autre moyen de transmission que le courrier électronique ordinaire non sécurisé, veuillez nous en aviser.
NOTICE: This privileged and confidential email is intended only for the individual or entity to whom it is addressed. With regard to all others, any action related with this email as well as any reading, reproduction, transmission and/or dissemination in whole or in part of the information included in this email is prohibited. If you are not the addressee, immediately return the email to sender prior to destroying all copies. Even if this email is believed to be free from any virus, it is the responsibility of the recipient to make sure that it is virus exempt. Our communications to you may contain confidential information or information protected under solicitor-client privilege. Please advise if you wish us to use a mode of communication other than regular, unsecured e-mail in our communications with you.
________________________________
This message is sent in confidence for the addressee only. It may contain confidential or sensitive information. The contents are not to be disclosed to anyone other than the addressee. Unauthorised recipients are requested to preserve this confidentiality and to advise us of any errors in transmission. Any views expressed in this message are solely the views of the individual and do not represent the views of the College. Nothing in this message should be construed as creating a contract.
Hull College owns the email infrastructure, including the contents.
Hull College is committed to sustainability, please reflect before printing this email.
________________________________
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150330/57105d9e/attachment.html
More information about the users
mailing list