ECP

IAM David Bantz dabantz at alaska.edu
Tue Sep 26 19:27:48 EDT 2017


Perceived need for non-web SSO login with Duo 2FA to AWS [I'm assured not
all AWS services are available from the web admin interface] is pushing us
to deploy ECP, not currently in use here. I'm puzzled by two different
descriptions of deploying:

https://wiki.shibboleth.net/confluence/display/IDP30/ECPConfiguration looked
straightforward at first glance provided the JAAS authN configuration can
be different than the JAAS config used for "normal" web-based (we'd point
to Duo proxy to get 2FA for ECP).

But then a guru suggested we need to base configuration on RemoteUser:
https://wiki.shibboleth.net/confluence/display/IDP30/
RemoteUserInternalAuthnConfiguration
which is sufficiently generic I don't know where to begin.

Where do I begin? What are the major tasks needed to deploy ECP (with Duo
Proxy).?

David Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170926/e47930ba/attachment.html>


More information about the users mailing list