<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle" type="text/css">P {margin-top:0;margin-bottom:0;}</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;">Hi all,<br>
I want to know if there is any way to secure application deployed to PaaS with Shibboleth SP?<br>
With popularity of cloud computing, especially PaaS, I can see more and more application will be created and deployed to this environment. CloudBees, Elastic Beanstal, Google App Engine all provides great services to make developers life easier. But we want
 to integrate those application into SSO federations as well. <br>
But PaaS usually don't provide Apache module to install Shibboleth SP plus that may not be very secure. Is there any work, prototype, white paper how to do it securely.
<br>
One approach would be install Shibboleth SP on private network and communicate with application on PaaS using REST API with SSL and public key cryptography. Maybe Shibboleth SP already does it? I found new and exciting functionality in the product every day.<br>
<br>
</div>
</body>
</html>