Question - Shibboleth SP authentification IIS serveur - Virtual folder Windows - propagation des droits --- Question - Shibboleth SP authentication IIS server - Windows virtual folder - rights propagation
sebastien.ody at orange.com
sebastien.ody at orange.com
Tue Feb 28 14:23:42 UTC 2023
Thank you Scott,
Is there a way to configure shibboleth so that a user identified by shibboleth on IIS windows in saml is also identified in windows ?
Maybe a kerberos delegation with the windows user who launches shibboleth?
we get a session with the user in the format user at ourdomain (which is the same as the user who launches IIS).
Do yo have an example of this kind of configuration ?
Sébastien
Orange Restricted
-----Message d'origine-----
De : users <users-bounces at shibboleth.net> De la part de Cantor, Scott via users
Envoyé : lundi 27 février 2023 13:33
À : Shib Users <users at shibboleth.net>
Cc : Cantor, Scott <cantor.2 at osu.edu>
Objet : Re: Question - Shibboleth SP authentification IIS serveur - Virtual folder Windows - propagation des droits --- Question - Shibboleth SP authentication IIS server - Windows virtual folder - rights propagation
> What would be the configuration needed to make the user authenticated
> by shibboleht also be at windows level when accessing the virtual
> folder and its folder?
If you mean this:
https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2063696267/Roles
, I guess that's how, otherwise it's not a feature.
-- Scott
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
_________________________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.
More information about the users
mailing list