Banner 9 SAML
Craig Pluchinsky
craigp at iup.edu
Thu Nov 2 14:51:26 EDT 2017
I gave up and went the CAS route using the support in the IDPs. Initial
testing seems to be working. We are still pretty early in our deployment
though.
-------------------------------
Craig Pluchinsky
IT Services
Indiana University of Pennsylvania
724-357-3327
On Thu, 2 Nov 2017, Jeffrey Crawford wrote:
> We did get it to work but it's very custom, we had to create the following resolver which is released only to Banner:
>
> <!-- Used by Banner XE -->
> <resolver:AttributeDefinition
> id="bannerUdcIdentifier"
> xsi:type="ad:Simple"
> sourceAttributeID="uid">
> <resolver:Dependency
> ref="ldapSource" />
> <resolver:AttributeEncoder
> xsi:type="enc:SAML2String"
> name="UDC_IDENTIFIER" />
> </resolver:AttributeDefinition>
>
>
> Jeffrey E. Crawford
> Enterprise Service Team ^ ^
> / \ ^ / \ ^
> / \/ \ / \ / \
> / \/ \/ \
> / \
>
> You have been assigned this mountain to prove to others that it *can* be moved.
>
> On Wed, Nov 1, 2017 at 9:10 AM, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu> wrote:
> FWIW, we have come to the same conclusions(stick with CAS) with all of the Banner components EXCEPT for the newer Banner XE
> modules that began delivering in 2012. Those modules are built on the Grails platform where there are already spring
> security plugins developed for SAML2 implementation. Ellucian granted us permission to fully explore those plugins while
> they develop their own, without violating our support contract, and we have successfully implemented SAML2 for BannerXE.
> Again, we never got there with the legacy Banner versions/modules.
>
> Josh O'Dowd
> University of Montana
>
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Tom O'Neill
> Sent: Tuesday, October 31, 2017 6:22 PM
> To: Shib Users <users at shibboleth.net>
> Subject: RE: Banner 9 SAML
>
> Hi All,
>
> I've also run in to issues with SAML 2.0 integration for some of the Ellucian Banner 9 components, even when using their
> Ellucian Ethos Identity solution as the IdP.
> Until the SAML 2.0 support is more mature, I'm suggesting the continued use of CAS, whenever possible.
>
> Thanks,
>
> Tom O'Neill
>
> -----Original Message-----
> From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
> Sent: Friday, October 27, 2017 5:15 PM
> To: Shib Users <users at shibboleth.net>
> Subject: Re: Banner 9 SAML
>
> On 10/27/17, 4:01 PM, "users on behalf of Jorj Bauer" <users-bounces at shibboleth.net on behalf of jorj at temple.edu> wrote:
>
> > The problem is mostly avoidable with CAS
>
> Plenty of browsers will break with any use of iframes and you should assume any such use is impossible with this software.
> That is going to be increasingly true and is already mostly true. That applies to CAS or SAML.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
>
>
>
More information about the users
mailing list