Question for folks that use Shibboleth for their PeopleSoft environments.
Curry, Warren
whcurry at ufl.edu
Thu Jan 21 08:34:06 EST 2016
We run 8.54.15 and have been running SAML2 for years and across many upgrades. Initially and even currently we have at this point chosen to use a proxy front end to implement. 8- years ago we had to . More recently we chose to keep doing the proxy for it's flexibility and some features we have leveraged for user experience. In the proxy setup, we actually handle the saml2 on an Apache webserver, handle the SAML2 and then invoke the signon code for PS with data from their. Obviously these are tightly secured server pairs...
The proxy is matched with one of the web servers in pairs. SO each PS webserver has a front ended proxy and the entire setup is load balanced from an F5...
There should be material on this in the wiki.
We have chosen this because we can have flexibility with a splash page that actually is used to launch into the PS environment.
This is also working fine in our test Shib v3.21 that will go to production soon.
However we have about two years ago tested directly to the PS instances as I recall this was successful..
-whc
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Ewing, Bill
Sent: Wednesday, January 20, 2016 4:25 PM
To: Shib Users <users at shibboleth.net>
Subject: Question for folks that use Shibboleth for their PeopleSoft environments.
We are working with a vendor to host our PeopleSoft environment and they raised the following concerns out of the blue. My question is has anyone took note of these bullet points in their setup of shibboleth with PeopleSoft and would they be something for concern or would have a good response to someone raising these? Mainly want to understand are these valid concerns or more a factor of support documents not being updated or oracle wanting to steer people to their own sso?
E-SEC: Does PeopleSoft Support Security Assertion Markup Language (SAML)? (Doc ID 623055.1)
PeopleTools 8.5x
SAML support in PeopleTools 8.5x has a very specific and narrow use case.
* Only SAML version 1.1 is supported.
* SAML support in PeopleTools 8.5x is only for Web Services and is based on node to node certificate trust.
* SAML support in PeopleTools 8.5x does not subscribe to or implement any form of identity federation.
* SAML is not supported in PT 8.5x for external single signon. There is no web access user authentication native implementation of SAML with PeopleTools at this time. SAML describes a protocol as well as a token. PeopleSoft takes advantage of aspects of the token to support SAML based authentication with web services. We strongly recommend that customers do not implement custom SSO solutions because of the many security compromises and business continuity risks.
* There are no plans of supporting SAML 2.0 even with development currently developing on PT 8.54.
Thanks,
Bill
William Ewing, Senior Information Security Analyst
CISSP, MCSE, MCITP-EA, CCNA/CCDA
UT System - Office of Information Security & Compliance
210 West 6th Street
Austin, Texas 78701-3035
Phone: (512)499-4575
email: bewing at utsystem.edu<mailto:bewing at utsystem.edu>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160121/33300f42/attachment.html>
More information about the users
mailing list