Protocol extensions discussion -Shib or SAML first?

Phil Lello phil at dunlop-lello.uk
Sat Oct 31 06:55:12 EDT 2015


Hi all,

I've got a use case for a SAML extension for Shibboleth, and wondered if it
is better discussing here or on the SAML list first, given that my default
implementation would be Shibboleth.

I've been nibbling around the edges of integrating federated identities
with SSH. My thought process to date is that this should be handled by
teaching SSH to handle SAML, however it occurs to me that as long as the
SSH server has a mechanism to perform an authorisation check for an
identifiy/key combination, this can be tackled as a server-side issue,
hopefully resulting in wider implementation sooner.

So, what I'm interested in adding is a mechanism for
attribute/authorisation verification for a known set of data - e.g. a query
for validity of a given subject,atribute,attribute value combination. This
would allow, for example, collection of SSH public keys via web logins
(either as released attributes or on a configuration page), and for
verification of validity on every use of the private key.

An alternate use case would be for validating sign-up data, so that
manually collected attributes can be verified. For example, if the IdP
authenticates a user, but doesn't release attributes for the real name, it
would be useful for the SP to confirm that a subject is who they claim to
be on the sign-up page.

Best wishes,

Phil Lello
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151031/025b65b5/attachment.html>


More information about the users mailing list