Banner ERP using Shibboleth IdP?
Kevin Foote
kpfoote at uoregon.edu
Fri Sep 18 12:18:35 EDT 2015
> On Sep 18, 2015, at 7:56 AM, Steven Carmody <steven_carmody at brown.edu> wrote:
>
> On 9/18/15 10:26 AM, Liam Hoekenga wrote:
>>
>> So it is possible configure banner to use an IdP other than the wso2
>> based Ellucian IdP.
>> What that difficult? The information I've seen so far was just about
>> configuring the the Ellucian IdP to work with SAML and CAS SPs.
>
> With Banner 8.x you have to install and use BEIS -- Banner Enterprise Identity Services. This requires that you create yet another person identifier within BEIS; BEIS then maps that "universal" identifier to the identifier used by each of the (different) Banner Business systems (eg to PIDM for the Student system). Shib supplies that universal identifier to the BEIS SSO endpoint.
Steven is pretty much right here. The BEIS layer is necessary for “normalizing” what the Banner apps see as the incoming principal. Note, you only have to run the BEIS SSO module not the rest of the “identity service”, this is a win in that your actual IdM services and process don’t need to
get turned upside down to make this integration work. (A lot of the underlying BEIS data can be produced using views rather than entire new tables.) :-)
> We do use Shib to login to XE, but I'm embarrassed to tell you how we did it. I'm very much looking forward to moving to Shib IDP V3, and using its native CAS support to login to XE.
No embarrassment!
Ellucian makes a one-size-fits-all solution that in any real environment just doesn’t work with out IdM glue.
--------
thanks
kevin.foote
More information about the users
mailing list