Shibboleth SP comparison with Azure AD Application Proxy

Dave Perry Dave.Perry at hull-college.ac.uk
Mon Sep 5 06:40:53 EDT 2016


I have no experience of Azure AD personally, but have managed to deploy the Shibboleth SP behind Forefront TMG (now redundant admittedly, but it is a reverse proxy). I didn't set the rules, that was done by the TMG admin, but it's possible there so principle should be the same.


Dave

_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group

Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930

* Need a fast reply? Try elearning at hull-college.ac.uk *


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Kate Dawson
Sent: 05 September 2016 11:32
To: users at shibboleth.net
Subject: Re: Shibboleth SP comparison with Azure AD Application Proxy

Thanks for the quick response

On Mon, Sep 05, 2016 at 11:55:52AM +0200, Peter Schober wrote:
> * Kate Dawson <k4t at 3msg.es> [2016-09-05 11:17]:
> > 
> > https://wiki.shibboleth.net/confluence/display/SHIB2/SPReverseProxy
> 
> is not what you'd nornally need. Instead you'd deploy the Shibboleth 
> SP with the application and protect it end-to-end using the standard 
> SAML protocol (Web Browser SSO), no proxies involved.

I believe that we're trying to avoid placing applications "directly" on the internet, so reverse proxy to them.  I know, it's confused.. :-(


Instead of opening firewalls to a variety of hosts, a reverse proxy will access the applications, and users connect to that.


Thanks, 

Kate Dawson

**********************************************************************
This message is sent in confidence for the addressee
only. It may  contain confidential or sensitive
information.  The contents are not to be disclosed
to anyone other than the addressee.  Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission.  Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College.  Nothing in this
message should be construed as creating a contract.

Hull College Group owns the email infrastructure, including the contents.

Hull College Group is committed to sustainability, please reflect before printing this email.
**********************************************************************

TEXT


More information about the users mailing list