Moving away from kerberos auth

Cantor, Scott cantor.2 at osu.edu
Tue Jul 5 10:37:14 EDT 2016


> Shibboleth is currently the only system we run here that is authentication
> with Kerberos, so if there's another way we can successfully authenticate
> users internally using integrated authentication, and externally using
> credentials passed from a third party portal (we're keen to use CAS for its
> single sign on possibilities, and because we can run ADFS and Shibboleth
> alongside each other).

I'm not really understanding why you need a portal. The SPNEGO support in the IdP can co-exist with LDAP or Kerberos authentication via form, and it was designed (by SWITCH) to support things like network-driven use of the SPNEGO option.

You can also authenticate ADFS via Shibboleth without CAS.

-- Scott



More information about the users mailing list