Lastpass?
Cantor, Scott
cantor.2 at osu.edu
Tue Jun 11 18:14:20 EDT 2019
On 6/11/19, 5:27 PM, "users on behalf of IAM David Bantz" <users-bounces at shibboleth.net on behalf of dabantz at alaska.edu> wrote:
> Can LastPass rely on Shibboleth IdP for users' initial authentication (i.e., to LastPass)?
I believe from memory that when OSU did some evaluation of the enterprise service they have that it had SAML support, but there are real problems with that model. The ability to impersonate users from the IdP is a pretty serious concern when it comes to the kinds of secrets that end up in LastPass.
We don't use SSO with our PAM solution here, and I think that was a necessary decision. In turn, I also don't think it's appropriate for our PAM admins to have access to our IdP servers, key, etc., which is a common failing of some PAM systems, they give too much access to the "super user" of the PAM tool. They're just very atypical kinds of systems and don't mix well.
-- Scott
More information about the users
mailing list