How-to build a custom federation

romain.dauby at orange.com romain.dauby at orange.com
Thu Sep 17 04:32:23 EDT 2015


_Accuracy_ :
The two IDP are using the same LDAP and retrieve the same attributes 
(attribute-resolver.xml).
We have these two to migrate applications (with SP) from IDP v2 to v3.

I will continue to investigate.


On 17/09/2015 09:35, Peter Schober wrote:
> * romain.dauby at orange.com <romain.dauby at orange.com> [2015-09-17 09:15]:
>> Actually we have 2 identity providers in the company, we would like to build
>> a federation.
>> Each SP has it's own IDP and only one. The goal is if a user connect to a SP
>> with IDP1, he should not need to authenticate if he wants access to another
>> SP linked to IDP2. Using a WAYF is not needed.
> You still need discovery: Either an SP is "linked" (your term) to an
> IDP, meaning it will send all requests (if auth is needed) to one
> specific, hardcoded IDP -- in which case subjects from the other IDP
> cannot log in to that SP in the normal way -- or you'll have to ask
> the subject what IDP to use, on every SP, every time.
>
> Each SP has its own session, so having authenticated to one SP (from
> either IDP) will not magically create a session at the other SP.
> You'll always have to select a "log in" link and pick your IDP.
> SSO only applies to what happens after that: No explicit need to
> authenticate at a given IDP if you have already used that IDP and the
> session with that IDP is still alive.
>
>> IDP1 is v2.1.5
> That's 5 years old and ticks all the boxes on possible/available
> vulnerabilities, see
> https://wiki.shibboleth.net/confluence/display/SHIB2/SecurityAdvisories
>
>> Im looking for for a tutorial / guideline / how-to build a federation.
>> The wiki shibboleth with this article isn't helping me as much as Im noob :
>> https://wiki.shibboleth.net/confluence/display/SHIB2/BuildAFederation
> Sure, we're just gonna write another long piece explaining everything
> again, based on that alone. (Hint: Ask specific questions what is unclear.)
>
> For 2 SPs and 2 IDPs just make sure every SP has SAML Metadata
> available for both IDPs, and every IDP has SAML Metadata available for
> both SPs. Then add the Shibboleth EDS to both SPs (or deploy one
> "centrally" or use another SAMLDS implemetation) and you're done.
> -peter


-- 


*Romain DAUBY*
Ingénieur d'Etudes SI
*Orange Applications for Business*
SCE / OAB / DPO / DSPM / SIE

Bureau : +33 (0)5 57 57 99 64
romain.dauby at orange.com <mailto:romain.dauby at orange.com>

Immeuble le Concorde
22-26 quai de Bacalan
33300 BORDEAUX
www.orange-business.com/fr <http://www.orange-business.com/fr>


_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150917/fe35b7e1/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: obs_left.gif
Type: image/gif
Size: 2201 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20150917/fe35b7e1/attachment.gif>


More information about the users mailing list