Joining up Shibboleth, AD and ADFS

Cantor, Scott cantor.2 at osu.edu
Wed Jul 20 09:51:08 EDT 2016


> Thanks for the thoughts Peter. I appreciate the issues with integrating with
> ADFS, but we as an organisation are pushing Office 365 so we're stuck with it
> (IT would not look kindly if I said to bin ADFS). I don't dislike O365, just that it
> complicates our mix.

You're not stuck with it unless you choose to be, MS claims to have supported all of that stuff via SAML, and there are people who have confirmed that it works. At this point, it's about will and making choices.

> If, by 'or by making MS-ADFS a downstream system to the Shib IDP', you are
> referring to what I asked (user hits shibboleth, if they have no session get
> them to authenticate to ADFS whether on or off site) then that I think is the
> thing that will (to my mind) make this goal possible. Documentation on that I
> have not been able to find thus far.

There is none. If you want the IdP to proxy out to some oher authentication source, that requires custom work. Authentication is possible via RemoteUser of course, if you can do that, but you'd still need scripts or other custom code to pull in attributes somehow.

Personally, I would just give up SSO between the two if I was in that situaton (and I probably will be shortly, as I have administrators with the same "lack of will" to actually do the work to use SAML with O365).

-- Scott



More information about the users mailing list