WebEx with Cirqlive - generating isolated IdP cert
Rob Gorrell
rwgorrel at uncg.edu
Tue Feb 23 15:04:12 EST 2016
Recently, we decided to make a switch from Blackboard Collaborate to the
Webex platform and have happy SSO-enabled our WebEx installation. However,
to offer WebEx through our LMS (Canvas, which is also SSO-enabled), we plan
to make sure of a 3rd party called Cirqlive. Long story short, users have
two entry ways to use Webex... one by going directly to WebEx through the
traditional interface and another by way of Canvas and the Cirqlive (LTI
tool). So in order to make all this happen, Cirqlive wants to by design
play man-in-the-middle and needs access to our IdP's private key... nothing
something I'm at all comfortable giving out generally speaking. However,
since shibb supports handing of multiple keys, the though process is to
generate a unique private key only used for the WebEx relying party and
then feel more comfortable in allowing Cirqlive to have access to it
(protecting all the other SPs that aren't involved in this weird setup).
So my question is, what is the best way to generate a new IdP cert not to
replace the one our IdP is using, but an additional one that will be just
for WebEx? Can this be done with *./install.sh renew-cert *and rather than
replace, just keep the old and new and plumb the new into the WebEx relying
party? Am I thinking about this correctly? Anybody else using WebEx with
Cirqlive?
This architecture I am referring to can be seen as Architecture #1 in
Cirqlive's own documentation:
https://documentation.cirqlive
.com/manuals/SSO/Overview_Multi-Source_SAML_Authentication_with_WebEx_(MEETS).pdf
https://documentation.cirqlive
.com/manuals/SSO/Multi-Source_SAML_Authentication_with_WebEx_(MEETS).pdf
-Rob
--
Robert W. Gorrell
Systems Architect, Identity and Access Management
University of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160223/85c5f3f8/attachment.html>
More information about the users
mailing list