Installation Resources
Fred Newtz (frnewtz)
frnewtz at cisco.com
Fri Feb 10 16:16:01 EST 2017
Rich,
Thanks! This was very helpful. I am just trying to document integrating our third party Service Provider with Shibboleth. So it doesn’t really matter what the configuration is as long as I can get it to talk to our SP. WE integrate with ADFS as well and have that integration documented and working right now. We have a documented “working” configuration with Shibboleth 2, but not with 3. I have tried, unsuccessfully, to convert the Shib 2 configuration to Shib 3 configuration.
I agree though. That is the best thing about Shibboleth. You have infinite customizability. That is also a detriment, but not one that insurmountable. I just want a working backend configuration that I can use to then get a working IdP/SP integration. I will get there though. I have found several links, but none that end up with an operational configuration when I am finished.
Thanks,
Fred
On 2/10/17, 12:09 PM, "users on behalf of Rich Graves" <users-bounces at shibboleth.net on behalf of rgraves at carleton.edu> wrote:
Fred, if you really only want very simple SAML from AD to a small
number of commercial SPs, then you might be happier with Microsoft's
ADFS or even the very limited ability of Google Apps to act as a SAML
IdP. Use Shibboleth if you have more specific needs for federation,
security, stability, open standards, and flexibility.
It seems that you want a "distribution," not upstream code. That's fine.
If you prefer or can deal with Docker containerization, then you might
want to start with one of these:
https://github.com/Unicon/shibboleth-idp-dockerized
https://spaces.internet2.edu/display/TPD/Shibboleth-IdP+Virtual+Machine+Documentation
If you don't like Docker and have a specific use case, then look to
the relevant federation or user community. For example, the InCommon
Federation that would link you to the biggest US and European research
universities and their vendors has simplified step-by-step directions
for RHEL7 here:
https://spaces.internet2.edu/pages/viewpage.action?pageId=49841792
Note that InCommon is documenting a limited feature set of the
year-old version 3.2.1, which was superseded by 3.3 in November
(typically there are only a couple versions per year, and
compatibility between minor versions is pretty solid unless you do
something unusual). The upstream Shibboleth documentation is
necessarily more technical, up to date, and complicated than these
distribution-specific and federation-specific derivatives.
Shibboleth.net cannot reasonably provide "quick start" because there
are too many variables.
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list