Question - Shibboleth SP authentification IIS serveur - Virtual folder Windows - propagation des droits --- Question - Shibboleth SP authentication IIS server - Windows virtual folder - rights propagation
sebastien.ody at orange.com
sebastien.ody at orange.com
Mon Feb 27 11:21:53 UTC 2023
Version Francaise
------------------
Bonjour la communauté,
Nous avons déployé un shibboleth SP sur un serveur windows 2019 avec IIS 8.
Nous avons configuré une authentification saml avec un fourniseur (idp) d'identié tier.
L'authentification fonctionne bien, nous récupérons bien les informations suivantes dans une session shibboleth:
* Adresse mail
* Nom prénom
* samaccountname
Le serveur Web IIS expose un serveur de fichier avec des droits (partage ntfs).
Nous avons un dossier par utilisateur et seul l'utilisateur (propriétaire du dossier) peut y accéder.
Nous avons créé un virtual folder IIS pour accéder à ces dossiers (dossier accéssible que par l'utilisateur courant).
Les utilisateurs peuvent accéder a leur dossier en lecture seule avec le mode d'authtenfication IIS windows http 401 challenge.
Nous souhaitons désactiver ce mode au profit du saml, IIS recoit bien le samaccountname (visible dans les logs d'accés IIS),cependant l'authenification ne semble pas se propager au niveau windows.
Quelle serait la configuration necessaire pour faire en sorte que l'utilisateur authentifié par shibboleht le soit aussi au niveau windows au moment d'accéder au virtual folder et à son dossier ?
Merci par avance pour votre aide,
English version
---------------------
Dear community,
We deployed a shibboleth SP on a windows 2019 server with IIS 8.
We have configured a saml authentication with a third party identity provider (idp).
The authentication is working fine, we are getting the following information in a shibbolethsession:
- Email address
- First name
- samaccountname
The IIS web server exposes a file server with rights (ntfs share).
We have one folder per user and only the user (owner of the folder) can access it.
We have created a virtual IIS folder to access these folders (folder accessible only by the current user).
Users can access their folder in read-only mode with the IIS windows http 401 challenge authentication mode.
We will disable this mode in favor of saml, IIS receives the samaccountname (visible in the IIS access logs), however the authentication does not seem to propagate to the windows level.
What would be the configuration needed to make the user authenticated by shibboleht also be at windows level when accessing the virtual folder and its folder?
Thanks in advance for your help,
[cid:image001.gif at 01D94AA6.113542B0]
Ody Sébastien
Business&Décision OBS
Orange Restricted
_________________________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230227/840f8cd4/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.gif
Type: image/gif
Size: 2261 bytes
Desc: image001.gif
URL: <http://shibboleth.net/pipermail/users/attachments/20230227/840f8cd4/attachment.gif>
More information about the users
mailing list