MS Autopilot with Shibboleth

Cantor, Scott cantor.2 at osu.edu
Wed Oct 30 16:17:20 UTC 2024


> Thanks for the reply. I just want to make sure I understand
> you correctly. You deployed only the ADFS proxy -- you didn't
> actually need to build an ADFS cluster in your domain? So the
> proxy handled the WS-Federation requests,

I would caution that anything that allows for that is just doing WS-Federation passively, because that's all you could plausibly proxy to SAML (the client has to be a browser in other words).

True WS-Trust (i.e. WS-federation active profile) would not be proxiable, and doesn't involve browser clients. It's more like ECP in that regard, but proxying active client protocols "isn't a thing" generally speaking, because of the lack of inherent composability.

-- Scott




More information about the users mailing list