Joining up Shibboleth, AD and ADFS
Peter Schober
peter.schober at univie.ac.at
Wed Jul 20 10:10:10 EDT 2016
* Dave Perry <Dave.Perry at hull-college.ac.uk> [2016-07-20 15:07]:
> Thanks for the thoughts Peter. I appreciate the issues with
> integrating with ADFS, but we as an organisation are pushing Office
> 365 so we're stuck with it (IT would not look kindly if I said to
> bin ADFS). I don't dislike O365, just that it complicates our mix.
What Scott said. You can do all of this without using MS-ADFS, but you
can certainly keep MS-ADFS for whatever purposes you want. E.g. there
will likely be other services that do not support all desirable parts
of their functionality via SAML.
> If, by 'or by making MS-ADFS a downstream system to the Shib IDP',
> you are referring to what I asked (user hits shibboleth, if they
> have no session get them to authenticate to ADFS whether on or off
> site)
I actually meant making the Shib IDP provide SSO and for MS-ADFS to be
a consumer of that (as a SAML SP -- which in turn may also be a
gateway/proxy to other services, possibly using other protocols).
That may not provide all the features you might need for other
services not mentioned in this thread, of course.
For stuff mentioned in this thread the Shib IDP alone would suffice.
-peter
More information about the users
mailing list