Banner 9 SAML

Jeffrey Crawford jeffreyc at ucsc.edu
Thu Nov 2 13:43:53 EDT 2017


We did get it to work but it's very custom, we had to create the following
resolver which is released only to Banner:

    <!-- Used by Banner XE -->
    <resolver:AttributeDefinition
      id="bannerUdcIdentifier"
      xsi:type="ad:Simple"
      sourceAttributeID="uid">
        <resolver:Dependency
          ref="ldapSource" />
        <resolver:AttributeEncoder
        xsi:type="enc:SAML2String"
        name="UDC_IDENTIFIER" />
    </resolver:AttributeDefinition>


Jeffrey E. Crawford
Enterprise Service Team <jeffreyc at ucsc.edu>
    ^         ^
   / \  ^    / \    ^
  /   \/ \  /   \  / \
 /        \/     \/   \
/                      \

You have been assigned this mountain to prove to others that it *can* be
moved.

On Wed, Nov 1, 2017 at 9:10 AM, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu>
wrote:

> FWIW,  we have come to the same conclusions(stick with CAS) with all of
> the Banner components EXCEPT for the newer Banner XE modules that began
> delivering in 2012.  Those modules are built on the Grails platform where
> there are already spring security plugins developed for SAML2
> implementation.  Ellucian granted us permission to fully explore those
> plugins while they develop their own, without violating our support
> contract, and we have successfully implemented SAML2 for BannerXE.  Again,
> we never got there with the legacy Banner versions/modules.
>
> Josh O'Dowd
> University of Montana
>
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Tom O'Neill
> Sent: Tuesday, October 31, 2017 6:22 PM
> To: Shib Users <users at shibboleth.net>
> Subject: RE: Banner 9 SAML
>
> Hi All,
>
> I've also run in to issues with SAML 2.0 integration for some of the
> Ellucian Banner 9 components, even when using their Ellucian Ethos Identity
> solution as the IdP.
> Until the SAML 2.0 support is more mature, I'm suggesting the continued
> use of CAS, whenever possible.
>
> Thanks,
>
>     Tom O'Neill
>
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor,
> Scott
> Sent: Friday, October 27, 2017 5:15 PM
> To: Shib Users <users at shibboleth.net>
> Subject: Re: Banner 9 SAML
>
> On 10/27/17, 4:01 PM, "users on behalf of Jorj Bauer" <
> users-bounces at shibboleth.net on behalf of jorj at temple.edu> wrote:
>
> > The problem is mostly avoidable with CAS
>
> Plenty of browsers will break with any use of iframes and you should
> assume any such use is impossible with this software. That is going to be
> increasingly true and is already mostly true. That applies to CAS or SAML.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171102/23fd4fe6/attachment.html>


More information about the users mailing list