Shibboleth / CAS / Office 365 / ECP
Marvin Addison
marvin.addison at gmail.com
Mon Nov 30 20:13:37 EST 2015
>
> Using shibboleth idp 2.4.4 with a frontend of CAS, been working perfectly
> for ages. Then Office 365 came along. We are using it against our
> shibboleth server, it all seems to work, but if you run the Microsoft
> Connectivity Analyzer it shows errors with ECP.
>
> I have configured it according to the page :
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableECP
>
>From that page:
"The most common mechanism for this will be HTTP Basic Authentication"
It also mentions client TLS. In any case it requires a non-interactive
authentication method. Obviously putting CAS in front of the IdP for all
SAML profiles is not compatible with the above requirement. You would need
to opt ECP out of CAS authentication for starters, which you could probably
do by tweaking servlet filter-mapping paths (assuming that's how you're
configuring the integrated CAS client).
M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151201/0b9a4aa0/attachment.html>
More information about the users
mailing list