Configuring RemoteUser checkHeaders in IDP3
Rich Graves
rgraves at carleton.edu
Wed Jul 13 17:19:53 EDT 2016
> or you can do it in the resolver in more ways than I'm sure I could even
come up with
I don't know, you can come up with a lot.
I looked at c14 but ended up doing it the "dumb" way, by searching AD for
mail instead of samaccountname, because really, why not?
Context:
This was for another .edu that wanted a simple gateway from Google to
InCommon. They wanted to leverage Google's free 2-Step Verification and
thought it was simpler for users to see only the familiar Google sign-in
form instead of a locally branded sign-on page.
They could have protected /idp/Authn/RemoteUser with a shibboleth SP and
Google's SAML IDP, but they thought it would be simpler to use OpenID
Connect.
So, what we ended up is Google -> Apache+mod_auth_openidc -> Jetty -> Shibb
RemoteUser.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160713/9f4e6a84/attachment.html>
More information about the users
mailing list