Piloting config changes

Abernathy, Jeff jeffabernathy at wustl.edu
Fri May 24 13:47:39 UTC 2024


Hello everyone,

Looking for some guidance/ideas. We have a relatively large shibboleth implementation, but we have made the decision to move much of the authentication to Azure. We'll still keep Shib around to handle Incommon and some applications that are much better suited there. I get how to have shib look to Azure (great documentation about that) for auth.

But what I've got laid out is that we want to do a pilot and then phase in this change over time. Users would be in an AD group that would control the pilot behavior with Azure. If we had a separate username then password prompt, I think we could a check on the user and see if they are in the group and then go a different login flow. But we don't and instead would like to explore other options of controlling the login flow.

Would cookies be an option? Is there an obvious thing that I'm missing with URL that control where we would provide the auth (via our LDAP/Duo flow or our Azure flow)?

I'd appreciate any breadcrumbs you all could throw

thanks,
Jeff Abernathy
Washington University in St. Louis

________________________________
The materials in this message are private and may contain Protected Healthcare Information or other information of a sensitive nature. If you are not the intended recipient, be advised that any unauthorized use, disclosure, copying or the taking of any action in reliance on the contents of this information is strictly prohibited. If you have received this email in error, please immediately notify the sender via telephone or return mail.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240524/974f980d/attachment.htm>


More information about the users mailing list