Thank you for the answer, and after authentication? Is there a way to get some more information about user's context? Maybe after login?<div><br></div><div>What do you think is the best way to modify shibboleth's behaviour based on user's context? Should I edit xml files or is there a way to call some kind of shibboleth's API?</div>
<div><br></div><div>Many thanks,</div><div>Marco<br><br><div class="gmail_quote">On 7 March 2012 10:39, <span dir="ltr"><<a href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Send users mailing list submissions to<br>
<a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
<a href="http://shibboleth.net/mailman/listinfo/users" target="_blank">http://shibboleth.net/mailman/listinfo/users</a><br>
or, via email, send a message with subject or body 'help' to<br>
<a href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a><br>
<br>
You can reach the person managing the list at<br>
<a href="mailto:users-owner@shibboleth.net">users-owner@shibboleth.net</a><br>
<br>
When replying, please edit your Subject line so it is more specific<br>
than "Re: Contents of users digest..."<br>
<br>
<br>
Today's Topics:<br>
<br>
1. Re: Custom Remote User Handler (Chad La Joie)<br>
2. Re: Custom Remote User Handler (Christopher Bland)<br>
3. Re: Custom Remote User Handler (Chad La Joie)<br>
4. Re: WAYF no longer linking correctly (Tom Scavo)<br>
5. User's context (Marco Zanini)<br>
6. Re: User's context (Chad La Joie)<br>
<br>
<br>
----------------------------------------------------------------------<br>
<br>
Message: 1<br>
Date: Tue, 6 Mar 2012 12:18:53 -0500<br>
From: Chad La Joie <<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>><br>
Subject: Re: Custom Remote User Handler<br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Message-ID:<br>
<CACTY7uCEeZ2dU=<a href="mailto:tEx7aM3M4Kd2Q1Z-ODjSebM4U-S6Dv9d23OQ@mail.gmail.com">tEx7aM3M4Kd2Q1Z-ODjSebM4U-S6Dv9d23OQ@mail.gmail.com</a>><br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
Well, I think you're just confused about SAML in general. The public<br>
interface to the IdP are the SAML endpoints that it exposes. When the<br>
request that comes in is an authentication request then the IdP will<br>
try to authenticate a user via one of its configured authentication<br>
mechanisms. This document talks about how the authentication<br>
mechanism is selected:<br>
<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn</a><br>
<br>
Why don't you start from the beginning and tell us what you're trying<br>
to accomplish instead of starting with question about specific<br>
configuration changes. The answer may be "you don't need to do<br>
anything special".<br>
<br>
<br>
On Tue, Mar 6, 2012 at 12:10, Christopher Bland <<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>> wrote:<br>
><br>
> Chad,<br>
><br>
> Now I'm confused.? In our current implementation we are using a SAML<br>
> profile (<a href="https://idp.fdu.edu/idp/profile/SAML2/Redirect/SSO" target="_blank">https://idp.fdu.edu/idp/profile/SAML2/Redirect/SSO</a>) but I do not<br>
> believe there is a remote user profile or at least I didn't get that from my<br>
> reading on setting remote user up.? Clearly I need to expand my<br>
> understanding of this.? I think I am missing the link between login handlers<br>
> and profiles.<br>
><br>
> Any suggested docs?<br>
><br>
> -Chris<br>
><br>
><br>
> On 3/6/12 11:57 AM, Chad La Joie wrote:<br>
><br>
> No, you can not directly target URLs used by the authentication engine.<br>
><br>
> On Tue, Mar 6, 2012 at 11:54, Christopher Bland <<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>> wrote:<br>
><br>
> Based on my reading and understanding I should be able to specify<br>
> <a href="https://idp.fdu.edu/idp/Authn/GoogleApps" target="_blank">https://idp.fdu.edu/idp/Authn/GoogleApps</a> as my " Sign-in page URL".<br>
><br>
><br>
> --<br>
> Chad La Joie<br>
> <a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
> trusted identities, delivered<br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
><br>
><br>
><br>
> --<br>
> Christopher Bland<br>
> Systems Manager<br>
> Information Systems and Technology<br>
> 1000 River Road, Teaneck NJ 07666<br>
> Mail Stop: T-BH1-01<br>
> : <a href="tel:201-692-2414" value="+12016922414">201-692-2414</a> | : <a href="tel:201-692-2494" value="+12016922494">201-692-2494</a> | : <a href="mailto:chris@fdu.edu">chris@fdu.edu</a><br>
> "Fairleigh Dickinson University will never<br>
> ?????????????????????????????????ask for your password. Please do not<br>
> share it with others!"<br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
<br>
--<br>
Chad La Joie<br>
<a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
trusted identities, delivered<br>
<br>
<br>
------------------------------<br>
<br>
Message: 2<br>
Date: Tue, 06 Mar 2012 13:24:18 -0500<br>
From: Christopher Bland <<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>><br>
Subject: Re: Custom Remote User Handler<br>
To: <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
Message-ID: <<a href="mailto:4F565652.6050902@fdu.edu">4F565652.6050902@fdu.edu</a>><br>
Content-Type: text/plain; charset="iso-8859-1"<br>
<br>
Chad,<br>
<br>
Thanks for the link to IdpUserAuthn doc. I had read it before dealing<br>
with another issue but totally missed my current need to specify the<br>
authentication method in Google's custom relying party tag. Do you think<br>
that the following changes will work:<br>
<br>
relying-party.xml<br>
<RelyingParty id="<a href="http://google.com" target="_blank">google.com</a>"<br>
provider="<a href="https://idp.fdu.edu/idp/shibboleth" target="_blank">https://idp.fdu.edu/idp/shibboleth</a>"<br>
defaultAuthenticationMethod="??????? not sure of appropriate class for<br>
remote user ???????"<br>
defaultSigningCredentialRef="IdPCredential"><br>
<ProfileConfiguration xsi:type="saml:SAML2SSOProfile"<br>
encryptAssertions="never" encryptNameIds="never" /><br>
</RelyingParty><br>
<br>
handler.xml<br>
<ph:LoginHandler xsi:type="ph:RemoteUser"><br>
<ph:protectedServletPath="/idp/Authn/GoogleApps"><br>
<ph:AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:?????????</ph:AuthenticationMethod><br>
(don't want to use unspecified because then it becomes default)<br>
</ph:LoginHandler><br>
<br>
web.xml<br>
<servlet><br>
<servlet-name>GoogleAppsAuthHandler</servlet-name><br>
<servlet-class>edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserAuthServlet</servlet-class><br>
<load-on-startup>5</load-on-startup><br>
</servlet><br>
<br>
<servlet-mapping><br>
<servlet-name>GoogleAppsAuthHandler</servlet-name><br>
<url-pattern>/Authn/GoogleApps</url-pattern><br>
</servlet-mapping><br>
<br>
http.conf<br>
<Location /idp/Authn/GoogleApps><br>
AuthType Basic AuthName "Identity Provider Authentication"<br>
AuthUserFile /PATH/TO/USER/FILE<br>
require valid-user<br>
</Location><br>
<br>
<br>
-Chris<br>
<br>
On 3/6/12 12:18 PM, Chad La Joie wrote:<br>
> Well, I think you're just confused about SAML in general. The public<br>
> interface to the IdP are the SAML endpoints that it exposes. When the<br>
> request that comes in is an authentication request then the IdP will<br>
> try to authenticate a user via one of its configured authentication<br>
> mechanisms. This document talks about how the authentication<br>
> mechanism is selected:<br>
> <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn</a><br>
<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <a href="http://shibboleth.net/pipermail/users/attachments/20120306/c829c6e8/attachment-0001.html" target="_blank">http://shibboleth.net/pipermail/users/attachments/20120306/c829c6e8/attachment-0001.html</a><br>
<br>
------------------------------<br>
<br>
Message: 3<br>
Date: Tue, 6 Mar 2012 13:31:37 -0500<br>
From: Chad La Joie <<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>><br>
Subject: Re: Custom Remote User Handler<br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Message-ID:<br>
<<a href="mailto:CACTY7uAGqzWcgW%2B8EcOmMK0GtbNjUQ0AN901gbKdwZtAKFyuwQ@mail.gmail.com">CACTY7uAGqzWcgW+8EcOmMK0GtbNjUQ0AN901gbKdwZtAKFyuwQ@mail.gmail.com</a>><br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
You will need to pick a URI for your custom method. You can *not* use<br>
the urn:oasis:names:tc:SAML namespace as that's controlled by the SAML<br>
committee. But it's just a URI so pick a URL you control.<br>
<br>
On Tue, Mar 6, 2012 at 13:24, Christopher Bland <<a href="mailto:chris@fdu.edu">chris@fdu.edu</a>> wrote:<br>
> Chad,<br>
><br>
> Thanks for the link to IdpUserAuthn doc.? I had read it before dealing with<br>
> another issue but totally missed my current need to specify the<br>
> authentication method in Google's custom relying party tag. Do you think<br>
> that the following changes will work:<br>
><br>
> relying-party.xml<br>
> ??? <RelyingParty id="<a href="http://google.com" target="_blank">google.com</a>"<br>
> ??????????? provider="<a href="https://idp.fdu.edu/idp/shibboleth" target="_blank">https://idp.fdu.edu/idp/shibboleth</a>"<br>
> ??????????? defaultAuthenticationMethod="??????? not sure of appropriate<br>
> class for remote user ???????"<br>
> ??????????? defaultSigningCredentialRef="IdPCredential"><br>
> ??????? <ProfileConfiguration xsi:type="saml:SAML2SSOProfile"<br>
> encryptAssertions="never" encryptNameIds="never" /><br>
> ??? </RelyingParty><br>
><br>
> handler.xml<br>
> ??? <ph:LoginHandler xsi:type="ph:RemoteUser"><br>
> ??????? <ph:protectedServletPath="/idp/Authn/GoogleApps"><br>
><br>
> <ph:AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:?????????</ph:AuthenticationMethod><br>
> (don't want to use unspecified because then it becomes default)<br>
> ??? </ph:LoginHandler><br>
><br>
> web.xml<br>
> ??? <servlet><br>
> ??????? <servlet-name>GoogleAppsAuthHandler</servlet-name><br>
><br>
> <servlet-class>edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserAuthServlet</servlet-class><br>
> ??????? <load-on-startup>5</load-on-startup><br>
> ??? </servlet><br>
><br>
> ??? <servlet-mapping><br>
> ??????? <servlet-name>GoogleAppsAuthHandler</servlet-name><br>
> ??????? <url-pattern>/Authn/GoogleApps</url-pattern><br>
> ??? </servlet-mapping><br>
><br>
> http.conf<br>
> ??? <Location /idp/Authn/GoogleApps><br>
> ????????? AuthType Basic AuthName "Identity Provider Authentication"<br>
> ????????? AuthUserFile /PATH/TO/USER/FILE<br>
> ????????? require valid-user<br>
> ??? </Location><br>
><br>
><br>
> -Chris<br>
><br>
><br>
> On 3/6/12 12:18 PM, Chad La Joie wrote:<br>
><br>
> Well, I think you're just confused about SAML in general. The public<br>
> interface to the IdP are the SAML endpoints that it exposes. When the<br>
> request that comes in is an authentication request then the IdP will<br>
> try to authenticate a user via one of its configured authentication<br>
> mechanisms. This document talks about how the authentication<br>
> mechanism is selected:<br>
> <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn</a><br>
><br>
><br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
--<br>
Chad La Joie<br>
<a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
trusted identities, delivered<br>
<br>
<br>
------------------------------<br>
<br>
Message: 4<br>
Date: Tue, 6 Mar 2012 19:14:45 -0500<br>
From: Tom Scavo <<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>><br>
Subject: Re: WAYF no longer linking correctly<br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Message-ID:<br>
<CAEtu=dNP-oebbRYF5MtGSAcT=<a href="mailto:JL59U1u1KYeW10uBQpVJP4aCg@mail.gmail.com">JL59U1u1KYeW10uBQpVJP4aCg@mail.gmail.com</a>><br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
On Tue, Mar 6, 2012 at 10:41 AM, Chad La Joie <<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>> wrote:<br>
> And does that error occur if you run a recent version of the DS?<br>
> 1.1.3 is the latest.<br>
<br>
Rod should be able to answer that question immediately. In any case,<br>
InCommon has received multiple such reports of errors, so we will<br>
remove the embedded double quotes from InCommon metadata ASAP. That<br>
means tomorrow's signed metadata aggregate will not contain embedded<br>
double quotes.<br>
<br>
Tom Scavo<br>
Operations Manager<br>
InCommon.org<br>
<br>
> On Tue, Mar 6, 2012 at 10:19, Tom Scavo <<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>> wrote:<br>
>> On Tue, Mar 6, 2012 at 10:05 AM, Gabriel Jimenez <<a href="mailto:Gabe.Jimenez@nau.edu">Gabe.Jimenez@nau.edu</a>> wrote:<br>
>>><br>
>>> We are using shibboleth-discovery-service-1.1.0.<br>
>><br>
>> Then I believe this is a bug and you should file an issue in Shibboleth jira.<br>
>><br>
>> Tom<br>
>> --<br>
>> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
><br>
><br>
><br>
> --<br>
> Chad La Joie<br>
> <a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
> trusted identities, delivered<br>
> --<br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
------------------------------<br>
<br>
Message: 5<br>
Date: Wed, 7 Mar 2012 10:06:53 +0000<br>
From: Marco Zanini <<a href="mailto:marco.zanini@lero.ie">marco.zanini@lero.ie</a>><br>
Subject: User's context<br>
To: <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
Message-ID:<br>
<CAG1Po3t9SAOZGBCWJNgs7STRd9RQ644c=<a href="mailto:bOqn65LAoTX4oE9Cg@mail.gmail.com">bOqn65LAoTX4oE9Cg@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="iso-8859-1"<br>
<br>
Hi to all,<br>
I am about to develop an application to apply different countermeasures<br>
depending on the user's context. I would like for example the user to use<br>
different types of login (username/password, two-step authentication) based<br>
on the context. I was thinking of developing an external authentication<br>
component for shibboleth.<br>
*What are the information about user's context that I can get from<br>
shibboleth when it calls my login handler?*<br>
I am using Google Apps as my service provider.<br>
<br>
Thank you,<br>
Marco<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <a href="http://shibboleth.net/pipermail/users/attachments/20120307/e7ab50ca/attachment-0001.html" target="_blank">http://shibboleth.net/pipermail/users/attachments/20120307/e7ab50ca/attachment-0001.html</a><br>
<br>
------------------------------<br>
<br>
Message: 6<br>
Date: Wed, 7 Mar 2012 05:39:21 -0500<br>
From: Chad La Joie <<a href="mailto:lajoie@itumi.biz">lajoie@itumi.biz</a>><br>
Subject: Re: User's context<br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Message-ID:<br>
<<a href="mailto:CACTY7uBeDCTOfddsrZJv_pgdxW_M6P-5ZhT66Xs4UZib-sui8Q@mail.gmail.com">CACTY7uBeDCTOfddsrZJv_pgdxW_M6P-5ZhT66Xs4UZib-sui8Q@mail.gmail.com</a>><br>
Content-Type: text/plain; charset=ISO-8859-1<br>
<br>
Well, prior to authentication the only thing you know is the protocol<br>
in use (SAML 1 or 2), the SP requesting the authentication, and if it<br>
requested a specific method. All of that is available in the<br>
LoginContext object available to the login handler.<br>
<br>
On Wed, Mar 7, 2012 at 05:06, Marco Zanini <<a href="mailto:marco.zanini@lero.ie">marco.zanini@lero.ie</a>> wrote:<br>
> Hi to all,<br>
> I am about to develop an application to apply different countermeasures<br>
> depending on the user's context. I would like for example the user to use<br>
> different types of login (username/password, two-step authentication) based<br>
> on the context. I was thinking of developing an external authentication<br>
> component for shibboleth.<br>
> What are the information about user's context that I can get from shibboleth<br>
> when it calls my login handler?<br>
> I am using Google Apps as my service provider.<br>
><br>
> Thank you,<br>
> Marco<br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
--<br>
Chad La Joie<br>
<a href="http://www.itumi.biz" target="_blank">www.itumi.biz</a><br>
trusted identities, delivered<br>
<br>
<br>
------------------------------<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
End of users Digest, Vol 9, Issue 19<br>
************************************<br>
</blockquote></div><br></div>