Configure SP using Apache to access ADFS IdP

Goldberg, Arthur P arthur.p.goldberg at mssm.edu
Mon May 17 02:34:12 UTC 2021


Thanks for your informative and quick reply Nate. It’s reassuring and helpful to have a short summary of steps.

In the meantime, I’ve learned that our security team would prefer that I authenticate with our MSFT Azure IdP. However, based on your description of the steps and the metadata our security team sent me, I suspect that the process will be the same.

Regards, Arthur

Nate Klingenstein ndk at signet.id<mailto:users%40shibboleth.net?Subject=Re:%20Re%3A%20Configure%20SP%20using%20Apache%20to%20access%20ADFS%20IdP&In-Reply-To=%3C0101017971ac1a18-7e347f76-25fc-4a36-856f-10f978423e89-000000%40us-west-2.amazonses.com%3E>

Arthur,

This should be relatively straightforward integration.  You need to load the ADFS instance's metadata in the SP, ensure that ADFS trusts the SP, tell ADFS to release the proper attributes, ensure the proper attributes are mapped to environment variables by the SP, and since this is a bilateral integration, add ADFS' entityID as the default in the SSO element in shibboleth2.xml.  That last step or the enforcement of protection may be what you're missing in terms of how to redirect the user directly to ADFS when authentication is required.

https://wiki.shibboleth.net/confluence/display/SP3/GettingStarted
https://wiki.shibboleth.net/confluence/display/SP3/ProtectContent

I'm not entirely sure what else to point you to.  I hope this helps.

Best wishes,
Nate.

--------
Signet, Inc.
The Art of Access ®

https://www.signet.id<https://www.signet.id/>


From: "Goldberg, Arthur P" <arthur.p.goldberg at mssm.edu>
Date: Saturday, May 15, 2021 at 2:26 PM
To: "users at shibboleth.net" <users at shibboleth.net>
Subject: Configure SP using Apache to access ADFS IdP

Hello Shibboleth community

I’m a newcomer to Shibboleth, SAML2 and ADFS.

I’m configuring a web app’s Service Provider. The web app runs on CentOS 7.9 and uses Apache 2.4 to handle authentication. Authentication will be provided by an ADFS service, which Mount Sinai operates as a cloud-based Azure AD.

I’ve read much of the great Shibboleth Service Provider documentation<https://wiki.shibboleth.net/confluence/display/SP3/Home>, but remain confused about how to properly reference the ADFS service as a SAML 2 IdP.

I’d greatly appreciate assistance if you have expertise in this combination of technologies.

Thanks
Arthur

--
Arthur Goldberg, PhD
Research Data Services
Scientific Computing
Associate Professor of Genetics and Genomic Sciences
Institute for Data Science and Genomic Technology
Mount Sinai School of Medicine

Arthur.Goldberg at mssm.edu<mailto:Arthur.Goldberg at mssm.edu>
646 526 5020
Zoom:  https://mssm.zoom.us/my/arthur.goldberg?pwd=LzByMGJOZC9wM3A2aHV6OU94eUtSQT09


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210517/53643f22/attachment.htm>


More information about the users mailing list