<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div>I have a project going which relates to this and brings social logins to service providers. &nbsp;If you are not referring to a specific codebase for your gateway version, then this would be an alternative gateway.</div><div><br></div><div>This one uses a custom coded oAuth gateway in a servlet at the IdP. &nbsp;An SP only needs a simple setting to request the custom authentication context to use it.</div><div><br></div><div>Additional attributes may be bound to the principal in our institutional LDAP service using our guest registration and groups management services, and these attributes will also be delivered (such as entitlements granting additional privileges). &nbsp;The identity of both the oAuth provider as well as the Shibboleth IdP can be sent as attributes to the SP (this was a requirement I see from an earlier e-mail from Keith on this topic).</div><div><br></div><div>This approach makes it extremely simple on the service provider side so that departments with limited IT staff could still use it with ease. &nbsp;On-campus departments are pretty familiar with setting up an SP at this point, but would have a difficult time integrating with oAuth independently.</div><div><br></div><div>I'll be showing this in a session at the next I2 in case anyone wants to take a look.</div><div><br></div><div>If this is of interest to your project, I will probably be rolling this out into our test IdP service in the not-too-distant future, and others wishing to try it out could connect there when it is ready.</div><div><br></div><div>Regards,</div><div>Russ.</div><div><br></div><div><div><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div style="font-size: 12px; ">==============================<br>Russell Beall<br>Programmer Analyst IV</div><div style="font-size: 12px; ">Enterprise Identity Management</div><div style="font-size: 12px; ">University&nbsp;of&nbsp;Southern California</div><div style="font-size: 12px; "><a href="mailto:beall@usc.edu">beall@usc.edu</a></div></div></div></span></div></span></span><span class="Apple-style-span" style="font-size: 12px; ">==============================</span>
</div><div><span class="Apple-style-span" style="font-size: 12px; "><br></span></div>
<br><div><div>On Jul 30, 2012, at 9:35 AM, Keith Hazelton wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">The MACE-Social Identity Working Group (<a href="https://spaces.internet2.edu/display/socialid/Home">https://spaces.internet2.edu/display/socialid/Home</a>)&nbsp;is beginning trials with two approaches to adding support for social identity providers to our SAML SPs. &nbsp;One is a social2SAML gateway, and Paul Caskey of UT System is standing up a trial gateway. &nbsp;The other is leveraging functionality new to the Shib SP in version 2.5 (release candidate now available) that allows authN plugins that would facilitate adding social IdPs to an SPs supported modes of authentication. &nbsp;See<div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPBackDoor">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPBackDoor</a><br><div><br></div><div>I am hoping people who wish to try the Shib SP "back door" approach to integrating Social IdPs will respond to this email with a statement of interest. &nbsp;As of this moment, Chris Hubing at the University of Pennsylvania and Keith Hazelton (UW-Madison and Project Bamboo) are committed to trials of such Shib SP-based solutions. &nbsp;Chris has an implementation configured and working and intends to document his approach once he irons out a couple issues.</div></div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp;Looking forward to hearing from interested parties, &nbsp; --Keith Hazelton</div></div>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></body></html>