Banner 9 SAML

Craig Pluchinsky craigp at iup.edu
Thu Nov 2 14:51:26 EDT 2017


I gave up and went the CAS route using the support in the IDPs.  Initial 
testing seems to be working.  We are still pretty early in our deployment 
though.


-------------------------------
Craig Pluchinsky
IT Services
Indiana University of Pennsylvania
724-357-3327


On Thu, 2 Nov 2017, Jeffrey Crawford wrote:

> We did get it to work but it's very custom, we had to create the following resolver which is released only to Banner:
> 
>     <!-- Used by Banner XE -->
>     <resolver:AttributeDefinition
>       id="bannerUdcIdentifier"
>       xsi:type="ad:Simple"
>       sourceAttributeID="uid">
>         <resolver:Dependency
>           ref="ldapSource" />
>         <resolver:AttributeEncoder
>         xsi:type="enc:SAML2String"
>         name="UDC_IDENTIFIER" />
>     </resolver:AttributeDefinition>
> 
> 
> Jeffrey E. Crawford
> Enterprise Service Team    ^         ^
>    / \  ^    / \    ^
>   /   \/ \  /   \  / \
>  /        \/     \/   \
> /                      \
> 
> You have been assigned this mountain to prove to others that it *can* be moved.
> 
> On Wed, Nov 1, 2017 at 9:10 AM, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu> wrote:
>       FWIW,  we have come to the same conclusions(stick with CAS) with all of the Banner components EXCEPT for the newer Banner XE
>       modules that began delivering in 2012.  Those modules are built on the Grails platform where there are already spring
>       security plugins developed for SAML2 implementation.  Ellucian granted us permission to fully explore those plugins while
>       they develop their own, without violating our support contract, and we have successfully implemented SAML2 for BannerXE. 
>       Again, we never got there with the legacy Banner versions/modules.
>
>       Josh O'Dowd
>       University of Montana
>
>       -----Original Message-----
>       From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Tom O'Neill
>       Sent: Tuesday, October 31, 2017 6:22 PM
>       To: Shib Users <users at shibboleth.net>
>       Subject: RE: Banner 9 SAML
>
>       Hi All,
>
>       I've also run in to issues with SAML 2.0 integration for some of the Ellucian Banner 9 components, even when using their
>       Ellucian Ethos Identity solution as the IdP.
>       Until the SAML 2.0 support is more mature, I'm suggesting the continued use of CAS, whenever possible.
>
>       Thanks,
>
>           Tom O'Neill
>
>       -----Original Message-----
>       From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
>       Sent: Friday, October 27, 2017 5:15 PM
>       To: Shib Users <users at shibboleth.net>
>       Subject: Re: Banner 9 SAML
>
>       On 10/27/17, 4:01 PM, "users on behalf of Jorj Bauer" <users-bounces at shibboleth.net on behalf of jorj at temple.edu> wrote:
>
>       > The problem is mostly avoidable with CAS
>
>       Plenty of browsers will break with any use of iframes and you should assume any such use is impossible with this software.
>       That is going to be increasingly true and is already mostly true. That applies to CAS or SAML.
>
>       -- Scott
> 
>
>       --
>       To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>       --
>       To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>       --
>       To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> 
> 
> 
>


More information about the users mailing list