advocacy tips

Cantor, Scott cantor.2 at osu.edu
Wed Nov 30 19:19:45 EST 2016


On 11/30/16, 7:02 PM, "users on behalf of Charlton Rose" <users-bounces at shibboleth.net on behalf of charltonrose at workfront.com> wrote:

> My company has several multi-tenant SaaS products and is looking for a good, customer-facing SSO solution. 
> At present, we're expending a lot of energy examining IDaaS providers (OneLogin, Ping, etc.) – some of them
> quite costly – and I've been trying to generate some interest in Shibboleth.  However, I'm dealing with some
> "perception" problems that I'd like some help getting through.  The primary perception problem is that because
> it's free to use, it's not going to be as capable, robust, flexible, or as easy to use as something we can pay for.

Are you talking IdP or SP? I would assume you mean SP if you're a SaaS provider.

The SP is really a function of integration strategy. It approaches SAML in general in a way that is hostile by design to the multi-tenant model (because that model is not really federation), but moreover it really is about integrating without integrating. Its design is focused on enterprise SSO and how to do that without embedding a specific technology into the application. That doesn't always, or really even usually, apply to commercial integrations into a platform. It's often not the right solution, but unfortunately most of the other RP software is so badly done that you give up key SAML features to use them.
    
> Yes, I know, it's a typical problem one runs into when trying to sell open source to a non-technical decision
> maker.  I'm not asking for those kinds of general arguments, but rather, arguments about IDP/SSO
> implementation.

If you mean the IdP and not the SP, I'm not sure I understand that being a "customer facing SSO solution" in the sense of a vendor with SaaS products. It may help me to understand the use case more.

Also, as a general statement, Shibboleth (IdP or SP) is *not* as easy to use as most other options, and nobody involved with the project claims that. It's not trying to be, and it couldn't support what it does while serving that goal. It could be made easier for a subset of use cases (on the IdP side) with additional resources we don't have at present, or a decision to spend what we do have on that problem almost exclusively.

-- Scott




More information about the users mailing list