Joining up Shibboleth, AD and ADFS
Cantor, Scott
cantor.2 at osu.edu
Wed Jul 20 10:18:18 EDT 2016
> I actually meant making the Shib IDP provide SSO and for MS-ADFS to be
> a consumer of that (as a SAML SP -- which in turn may also be a
> gateway/proxy to other services, possibly using other protocols).
> That may not provide all the features you might need for other
> services not mentioned in this thread, of course.
> For stuff mentioned in this thread the Shib IDP alone would suffice.
In effect it comes down to the O365 issue. If you end up needing WS-Trust support, then Shibboleth can't be the authenticator for ADFS in that mode. If you don't need WS-Trust support, you likely don't need ADFS other than because of recalcitrant admins/project managers.
-- Scott
More information about the users
mailing list