Shibboleth SP comparison with Azure AD Application Proxy
Kate Dawson
k4t at 3msg.es
Mon Sep 5 06:31:39 EDT 2016
Thanks for the quick response
On Mon, Sep 05, 2016 at 11:55:52AM +0200, Peter Schober wrote:
> * Kate Dawson <k4t at 3msg.es> [2016-09-05 11:17]:
> >
> > https://wiki.shibboleth.net/confluence/display/SHIB2/SPReverseProxy
>
> is not what you'd nornally need. Instead you'd deploy the Shibboleth
> SP with the application and protect it end-to-end using the standard
> SAML protocol (Web Browser SSO), no proxies involved.
I believe that we're trying to avoid placing applications "directly" on
the internet, so reverse proxy to them. I know, it's confused.. :-(
Instead of opening firewalls to a variety of hosts, a reverse proxy will
access the applications, and users connect to that.
Thanks,
Kate Dawson
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20160905/c672745b/attachment.sig>
More information about the users
mailing list